CVE-2024-11916

CVSS 3.1 Score 5.4 of 10 (medium)

Details

Published Jan 8, 2025
Updated: Jan 17, 2025
CWE ID 862
CWE ID 79

Summary

CVE-2024-11916: The WP Extended plugin for WordPress, up to version 3.0.11, is affected by a vulnerability that allows authenticated attackers with subscriber-level access or higher to bypass capability checks on several functions. This flaw enables the import and activation of arbitrary code snippets, posing a significant risk for unauthorized data modification and retrieval.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share