CVE-2024-13375
CVSS 3.1 Score 9.8 of 10 (high)
Details
Published Jan 18, 2025
CWE ID 620
Summary
CVE-2024-13375: A privilege escalation vulnerability affects the Adifier System plugin for WordPress. The flaw, present in versions up to 3.1.7, allows unauthenticated attackers to manipulate user details, including passwords, through the adifier_recover() function. By exploiting this weakness, adversaries can change passwords of arbitrary users, including administrators, enabling them to gain unauthorized access to those accounts.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.