CVE-2024-13146

CVSS 3.1 Score 8.8 of 10 (high)

Details

Published Mar 26, 2025
Updated: Mar 27, 2025

Summary

CVE-2024-13146 is a vulnerability affecting the Booknetic WordPress plugin before version 4.1.5. This issue permits unauthorized creation of Staff accounts by attackers. The plugin fails to implement Cross-Site Request Forgery (CSRF) protection during Staff account creation, allowing malicious actors to manipulate the function through a targeted CSRF attack. Consequently, attackers can add arbitrary Staff members with admin privileges to the WordPress site, posing a significant security risk. It is recommended that users update the plugin to the latest version to mitigate this vulnerability.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share