CVE-2024-12454

CVSS 3.1 Score 6.1 of 10 (medium)

Details

Published Dec 18, 2024
CWE ID 352

Summary

CVE-2024-12454: The Affiliate Program Suite's SliceWP Affiliates plugin for WordPress, versions up to 1.1.23, possesses a Cross-Site Request Forgery vulnerability. This arises from insufficient or absent nonce validation within a function, allowing unauthenticated attackers to execute malicious web scripts through forged requests. The exploitation of this weakness relies on tricking a site administrator into executing an action, such as clicking on a crafted link.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share