CVE-2024-12554
CVSS 3.1 Score 5.4 of 10 (medium)
Details
Published Dec 18, 2024
CWE ID 352
Summary
CVE-2024-12554 is a Cross-Site Request Forgery (CSRF) vulnerability impacting the Peter’s Custom Anti-Spam plugin for WordPress. Versions up to and including 3.2.3 are affected by this issue. The root cause lies in the lack of nonce validation on the cas_register_post() function. As a result, unauthenticated attackers can exploit this flaw by tricking administrators into performing certain actions, such as clicking on a malicious link. Successful exploitation allows the attacker to blacklist emails, posing a serious security risk.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.