CVE-2024-12606

CVSS 3.1 Score 4.3 of 10 (medium)

Details

Published Jan 10, 2025
CWE ID 862

Summary

CVE-2024-12606 is a vulnerability affecting the AI Scribe plugin for WordPress, specifically versions up to and including 2.3. This issue stems from a missing capability check on the engine_request_data() function, which enables authenticated attackers with Subscriber-level access or higher to unauthorizedly modify plugin settings. This vulnerability poses a risk to the integrity of plugin configurations and may lead to potential security breaches. Users are advised to update the plugin to a patched version as soon as possible to mitigate this threat.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share