CVE-2024-12545
CVSS 3.1 Score 5.4 of 10 (medium)
Details
Published Jan 4, 2025
CWE ID 352
CWE ID 862
CWE ID 863
Summary
CVE-2024-12545 is a Cross-Site Request Forgery (CSRF) vulnerability affecting the Scratch & Win plugin for WordPress. Versions up to and including 2.7.1 are impacted by this issue. The vulnerability stems from the lack of nonce validation on the reset_installation() function, which leaves the plugin open to unauthenticated attacks. An attacker can exploit this weakness by tricking a site administrator into executing a malicious link, enabling them to reset the plugin's installation.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Vendors
- WordPress