CVE-2024-12287

CVSS 3.1 Score 9.8 of 10 (high)

Details

Published Dec 18, 2024
CWE ID 287

Summary

CVE-2024-12287 is a newly disclosed vulnerability affecting the Biagiotti Membership plugin for WordPress. The issue, present in all versions up to 1.0.2, allows unauthenticated attackers to bypass the plugin's authentication process. Instead of verifying user identities before granting access, the plugin unwittingly authenticates users based on their email addresses alone. This shortcoming exposes a significant security risk, enabling attackers to log in as other users, potentially gaining administrator privileges if the targeted account holds such access.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share