CVE-2024-12454
CVSS 3.1 Score 6.1 of 10 (medium)
Details
Published Dec 18, 2024
CWE ID 352
Summary
CVE-2024-12454: The Affiliate Program Suite's SliceWP Affiliates plugin for WordPress, versions up to 1.1.23, possesses a Cross-Site Request Forgery vulnerability. This arises from insufficient or absent nonce validation within a function, allowing unauthenticated attackers to execute malicious web scripts through forged requests. The exploitation of this weakness relies on tricking a site administrator into executing an action, such as clicking on a crafted link.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.