CVE-2024-13356
CVSS 3.1 Score 6.5 of 10 (medium)
Details
Published Feb 4, 2025
CWE ID 352
Summary
CVE-2024-13356 is a Cross-Site Request Forgery (CSRF) vulnerability affecting the DSGVO All in one for WP plugin for WordPress. Versions up to 4.6 are impacted by this issue, which arises from insufficient or absent nonce validation in the user_remove_form.php file. An attacker can exploit this flaw by crafting a malicious request, compelling a site administrator to execute an action, such as clicking on a link, thereby enabling the attacker to delete admin user accounts without proper authorization.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Share