CVE-2024-12885

CVSS 3.1 Score 6.5 of 10 (medium)

Details

Published Jan 25, 2025
CWE ID 22

Summary

CVE-2024-12885 is a vulnerability affecting the Connections Business Directory plugin for WordPress. This issue allows authenticated attackers with Administrator-level access to delete arbitrary folders and their contents on the server. The vulnerability arises from insufficient file path validation during the process of deleting a Connections image directory, which can be exploited to delete directories outside of the intended image directory. Versions up to and including 10.4.66 are reportedly vulnerable.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share