CVE-2024-12419
CVSS 3.1 Score 6.5 of 10 (medium)
Details
Published Jan 7, 2025
CWE ID 94
Summary
CVE-2024-12419: The CF7 WOW Styler plugin for WordPress, versions up to 1.7.0, is susceptible to arbitrary shortcode execution. This vulnerability arises due to insufficient validation of user inputs, enabling unauthenticated assailants to execute arbitrary shortcodes. The issue also exposes a Reflected Cross-Site Scripting (XSS) risk. Although a patch was released in version 1.7.0 for the XSS vulnerability, the arbitrary shortcode execution issue persists.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.