CVE-2024-12636

CVSS 3.1 Score 4.3 of 10 (medium)

Details

Published Dec 25, 2024
CWE ID 352

Summary

CVE-2024-12636: The WP Legal Pages plugin for WordPress, used for creating Privacy Policies and Terms & Conditions, is susceptible to Cross-Site Request Forgery (CSRF) attacks. This vulnerability affects all versions up to 3.2.6. The 'create_popup_delete_process' function lacks proper nonce validation, enabling unauthenticated attackers to delete popups by tricking administrators into executing a malicious link. This poses a potential risk for data loss and unintended modifications to website content.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share