CVE-2024-12860

CVSS 3.1 Score 9.8 of 10 (high)

Details

Published Feb 18, 2025
Updated: Feb 21, 2025
CWE ID 620

Summary

CVE-2024-12860 is a privilege escalation vulnerability affecting the CarSpot – Dealership Wordpress Classified Theme for WordPress. The issue, present in all versions up to 2.4.3, stems from the theme's failure to adequately validate a token during password updates. This flaw enables unauthenticated attackers to manipulate user passwords, including those of administrators, paving the way for account takeover. Successful exploitation of this vulnerability grants attackers elevated access to the affected WordPress installation.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share