CVE-2024-12825

CVSS 3.1 Score 5.4 of 10 (medium)

Details

Published Feb 1, 2025
CWE ID 862

Summary

CVE-2024-12825 is a vulnerability affecting the Custom Related Posts plugin for WordPress. This issue allows authenticated attackers, with Subscriber-level access and above, to gain unauthorized access and modify data through three unsecured AJAX actions in versions up to 1.7.3. The consequence is that attackers can search posts and manipulate post relations, posing a potential security threat to WordPress websites using this plugin. It is recommended that users update the Custom Related Posts plugin to a version beyond 1.7.3 to mitigate this risk.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share