CVE-2024-12280
CVSS 3.1 Score 4.3 of 10 (medium)
Details
Summary
CVE-2024-12280 is a newly disclosed vulnerability in the WP Customer Area WordPress plugin. This issue allows attackers to delete logs through the plugin without proper CSRF protection. As a result, an unauthorized user can manipulate log data by carrying out a Cross-Site Request Forgery (CSRF) attack. An attacker can potentially gain insights into user activities or disrupt system functionality by exploiting this vulnerability. It is recommended that users update the plugin to the latest version, which reportedly includes the necessary CSRF protection, to mitigate this risk.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.