CVE-2024-12314

CVSS 3.1 Score 7.2 of 10 (high)

Details

Published Feb 18, 2025
Updated: Feb 24, 2025
CWE ID 524

Summary

CVE-2024-12314 is a cache poisoning vulnerability affecting the Rapid Cache plugin for WordPress. Versions up to 1.2.3 are vulnerable to this issue. The vulnerability arises due to the plugin storing HTTP headers in the cached data, allowing unauthenticated attackers to manipulate the headers with potential unsanitized Cross-Site Scripting (XSS) payloads. This can lead to security breaches and unauthorized code execution on vulnerable WordPress websites. It's crucial for WordPress users to update the Rapid Cache plugin to a version that fixes this vulnerability as soon as possible.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share