CVE-2024-12005
CVSS 3.1 Score 6.1 of 10 (medium)
Details
Summary
CVE-2024-12005 is a newly disclosed vulnerability affecting the WP-BibTeX plugin for WordPress. This issue, present in all versions up to 3.0.1, exposes a Cross-Site Request Forgery (CSRF) weakness. The root cause is a lack of proper nonce validation in the wp_bibtex_option_page() function, which in turn allows unauthenticated attackers to execute malicious web scripts. Attackers can exploit this vulnerability by tricking administrators into executing a malicious action, such as clicking a link, thereby enabling the injection of their malicious code. Users are advised to update their WP-BibTeX plugin to the latest version as soon as possible to mitigate this risk.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.