CVE-2024-12287
CVSS 3.1 Score 9.8 of 10 (high)
Details
Published Dec 18, 2024
CWE ID 287
Summary
CVE-2024-12287 is a newly disclosed vulnerability affecting the Biagiotti Membership plugin for WordPress. The issue, present in all versions up to 1.0.2, allows unauthenticated attackers to bypass the plugin's authentication process. Instead of verifying user identities before granting access, the plugin unwittingly authenticates users based on their email addresses alone. This shortcoming exposes a significant security risk, enabling attackers to log in as other users, potentially gaining administrator privileges if the targeted account holds such access.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.