CVE-2024-13231
CVSS 3.1 Score 5.3 of 10 (medium)
Details
Published Feb 19, 2025
CWE ID 862
Summary
CVE-2024-13231 is a vulnerability affecting the WordPress Portfolio Builder – Portfolio Gallery plugin. The issue stems from a missing capability check in the 'add_video' function, present in all versions up to 1.1.7. This flaw enables unauthenticated attackers to manipulate data by adding arbitrary videos to any portfolio gallery, posing a significant security risk.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Share