CVE-2024-12545

CVSS 3.1 Score 5.4 of 10 (medium)

Details

Published Jan 4, 2025
CWE ID 352
CWE ID 862
CWE ID 863

Summary

CVE-2024-12545 is a Cross-Site Request Forgery (CSRF) vulnerability affecting the Scratch & Win plugin for WordPress. Versions up to and including 2.7.1 are impacted by this issue. The vulnerability stems from the lack of nonce validation on the reset_installation() function, which leaves the plugin open to unauthenticated attacks. An attacker can exploit this weakness by tricking a site administrator into executing a malicious link, enabling them to reset the plugin's installation.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share