CVE-2024-12076

CVSS 3.1 Score 6.1 of 10 (medium)

Details

Published Jan 25, 2025
CWE ID 79

Summary

CVE-2024-12076 is a Cross-Site Request Forgery (CSRF) vulnerability affecting the Target Video Easy Publish plugin for WordPress. The flaw, present in all versions up to 3.8.3, stems from insufficient or missing nonce validation on key functions: resync_carousel(), seek_snapshot(), uploaded_cc(), and remove_cc(). Consequently, unauthenticated attackers can inject malicious web scripts by manipulating a user into executing a malicious action, such as clicking a deceptive link. This poses a significant risk to WordPress sites utilizing the Target Video Easy Publish plugin, necessitating immediate updates to mitigate the danger.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share