CVE-2024-13318

CVSS 3.1 Score 5.3 of 10 (medium)

Details

Published Jan 10, 2025
CWE ID 463

Summary

CVE-2024-13318 is a vulnerability affecting the Essential WP Real Estate plugin for WordPress. The issue stems from a missing capability check on the cl_delete_listing_func() function, which exists in all versions up to 1.1.3. Consequently, unauthenticated attackers are able to delete arbitrary pages and posts on affected WordPress sites. This represents a significant security risk, as it allows unauthorized modification of content. Upgrading to a patched version of the plugin is recommended to mitigate this vulnerability.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share