CVE-2024-12583
CVSS 3.1 Score 9.9 of 10 (high)
Details
Published Jan 4, 2025
CWE ID 1336
Summary
CVE-2024-12583 is a Remote Code Execution and Arbitrary File Read vulnerability affecting the Dynamics 365 Integration plugin for WordPress. Versions up to and including 1.3.23 are vulnerable to this issue. The root cause is the lack of input validation and sanitization on the plugin's render function. This weakness allows authenticated attackers with Contributor-level access or higher to inject and execute malicious code on the server.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.