CVE-2024-12385

CVSS 3.1 Score 6.1 of 10 (medium)

Details

Published Jan 18, 2025
CWE ID 352

Summary

CVE-2024-12385 is a Cross-Site Request Forgery (CSRF) vulnerability affecting the WP Abstracts plugin for WordPress versions 2.7.2 and below. The issue lies in the lack of nonce validation on the functions wpabstracts_load_status() and wpabstracts_delete_abstracts(). This weakness enables unauthenticated attackers to execute malicious web scripts by deceiving administrators into performing actions such as clicking on a malicious link. Successful exploitation could potentially lead to site defacement or data exfiltration. Users are advised to update the WP Abstracts plugin to the latest version to mitigate this risk.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share