CVE-2024-12554

CVSS 3.1 Score 5.4 of 10 (medium)

Details

Published Dec 18, 2024
CWE ID 352

Summary

CVE-2024-12554 is a Cross-Site Request Forgery (CSRF) vulnerability impacting the Peter’s Custom Anti-Spam plugin for WordPress. Versions up to and including 3.2.3 are affected by this issue. The root cause lies in the lack of nonce validation on the cas_register_post() function. As a result, unauthenticated attackers can exploit this flaw by tricking administrators into performing certain actions, such as clicking on a malicious link. Successful exploitation allows the attacker to blacklist emails, posing a serious security risk.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share