CVE-2024-12825
CVSS 3.1 Score 5.4 of 10 (medium)
Details
Published Feb 1, 2025
CWE ID 862
Summary
CVE-2024-12825 is a vulnerability affecting the Custom Related Posts plugin for WordPress. This issue allows authenticated attackers, with Subscriber-level access and above, to gain unauthorized access and modify data through three unsecured AJAX actions in versions up to 1.7.3. The consequence is that attackers can search posts and manipulate post relations, posing a potential security threat to WordPress websites using this plugin. It is recommended that users update the Custom Related Posts plugin to a version beyond 1.7.3 to mitigate this risk.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.