CVE-2024-12713

CVSS 3.1 Score 5.3 of 10 (medium)

Details

Published Jan 8, 2025
CWE ID 862

Summary

CVE-2024-12713 is a newly identified Information Exposure vulnerability affecting the SureForms – Drag and Drop Form Builder plugin for WordPress. This issue, present in all versions up to and including 1.2.2, allows unauthenticated attackers to export data from password-protected, private, or draft posts. The vulnerability arises due to a missing capability check, enabling unauthorized access to the handle_export_form() function. By exploiting this flaw, attackers can gain access to sensitive information that they should not be privy to. This vulnerability emphasizes the importance of applying software patches promptly to maintain optimal security for WordPress websites.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share