CVE-2024-12041
CVSS 3.1 Score 5.3 of 10 (medium)
Details
Summary
CVE-2024-12041 is a newly disclosed vulnerability in The Directorist plugin for WordPress, which is used for business directories and classified ads listings. This weakness allows unauthenticated attackers to retrieve sensitive user data through the /wp-json/directorist/v1/users/ endpoint. The information exposed includes usernames, email addresses, names, and possibly more. This vulnerability poses a significant risk as it can enable attackers to conduct targeted phishing or spamming campaigns, potentially leading to account takeover or identity theft. Users of the affected plugin are advised to update to the latest version as soon as possible to mitigate this risk.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.