CVE-2024-12219

CVSS 3.1 Score 6.1 of 10 (medium)

Details

Published Dec 17, 2024
CWE ID 352

Summary

CVE-2024-12219 is a vulnerability affecting the Stop Registration Spam plugin for WordPress. This issue allows for Cross-Site Request Forgery (CSRF) attacks, which can be exploited by unauthenticated attackers. The vulnerability stems from missing or incorrect nonce validation, making it possible for attackers to inject malicious web scripts into a site. To exploit this vulnerability, an attacker must trick a site administrator into performing an action, such as clicking on a malicious link. All versions of the plugin up to and including 1.23 are affected.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share