CVE-2024-13318
CVSS 3.1 Score 5.3 of 10 (medium)
Details
Published Jan 10, 2025
CWE ID 463
Summary
CVE-2024-13318 is a vulnerability affecting the Essential WP Real Estate plugin for WordPress. The issue stems from a missing capability check on the cl_delete_listing_func() function, which exists in all versions up to 1.1.3. Consequently, unauthenticated attackers are able to delete arbitrary pages and posts on affected WordPress sites. This represents a significant security risk, as it allows unauthorized modification of content. Upgrading to a patched version of the plugin is recommended to mitigate this vulnerability.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.