CVE-2024-12583

CVSS 3.1 Score 9.9 of 10 (high)

Details

Published Jan 4, 2025
CWE ID 1336

Summary

CVE-2024-12583 is a Remote Code Execution and Arbitrary File Read vulnerability affecting the Dynamics 365 Integration plugin for WordPress. Versions up to and including 1.3.23 are vulnerable to this issue. The root cause is the lack of input validation and sanitization on the plugin's render function. This weakness allows authenticated attackers with Contributor-level access or higher to inject and execute malicious code on the server.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share