CVE-2024-12322
CVSS 3.1 Score 8.8 of 10 (high)
Details
Published Jan 7, 2025
CWE ID 352
Summary
CVE-2024-12322: The ThePerfectWedding.nl Widget plugin for WordPress contains a Cross-Site Request Forgery (CSRF) vulnerability, affecting versions up to 2.8. This issue stems from insufficient or absent nonce validation in the 'update_option' function. Consequently, unauthorized attackers can manipulate the 'tpwKey' option with stored cross-site scripting (XSS) when administrators unknowingly execute a malicious link.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.