CVE-2024-12296
CVSS 3.1 Score 8.8 of 10 (high)
Details
Summary
CVE-2024-12296 is a vulnerability affecting the Apus Framework plugin for WordPress. The issue lies in the lack of capability checks on the 'import_page_options' function, allowing authenticated attackers with Subscriber-level access or higher to modify arbitrary options. This can be exploited to update the default registration role to administrator and enable user registration for attackers, enabling them to gain administrative access to a vulnerable WordPress site. This vulnerability poses a significant threat to websites utilizing the Apus Framework plugin and should be addressed promptly by updating to a patched version.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.