CVE-2024-12291
CVSS 3.1 Score 6.1 of 10 (medium)
Details
Summary
CVE-2024-12291 is a Cross-Site Request Forgery (CSRF) vulnerability affecting the ViewMedica 9 plugin for WordPress. versions up to 1.4.15 are susceptible to this issue. The flaw arises due to insufficient nonce validation on a specific function, allowing unauthenticated attackers to execute malicious web scripts by tricking administrators into performing a designated action, such as clicking on a malicious link. Successful exploitation of this vulnerability could lead to unintended changes or access to sensitive data within the WordPress site. Users are strongly advised to update their ViewMedica plugin to a patched version to mitigate this risk.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.