CVE-2024-13367
CVSS 3.1 Score 6.5 of 10 (medium)
Details
Published Jan 17, 2025
CWE ID 862
Summary
CVE-2024-13367 is a vulnerability affecting the Sandbox plugin for WordPress. This issue allows authenticated attackers with Subscriber-level access or higher to bypass a capability check on the export_download action. By exploiting this vulnerability, attackers can download an entire sandbox environment, potentially gaining access to sensitive files, such as the wp-config.php file. This vulnerability puts WordPress sites using outdated Sandbox plugin versions (up to and including 0.4) at risk.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.