CVE-2024-11916
CVSS 3.1 Score 5.4 of 10 (medium)
Details
Published Jan 8, 2025
Updated: Jan 17, 2025
CWE ID 862
CWE ID 79
Summary
CVE-2024-11916: The WP Extended plugin for WordPress, up to version 3.0.11, is affected by a vulnerability that allows authenticated attackers with subscriber-level access or higher to bypass capability checks on several functions. This flaw enables the import and activation of arbitrary code snippets, posing a significant risk for unauthorized data modification and retrieval.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.