CVE-2024-12385
CVSS 3.1 Score 6.1 of 10 (medium)
Details
Summary
CVE-2024-12385 is a Cross-Site Request Forgery (CSRF) vulnerability affecting the WP Abstracts plugin for WordPress versions 2.7.2 and below. The issue lies in the lack of nonce validation on the functions wpabstracts_load_status() and wpabstracts_delete_abstracts(). This weakness enables unauthenticated attackers to execute malicious web scripts by deceiving administrators into performing actions such as clicking on a malicious link. Successful exploitation could potentially lead to site defacement or data exfiltration. Users are advised to update the WP Abstracts plugin to the latest version to mitigate this risk.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.