CVE-2024-13411

CVSS 3.1 Score 6.4 of 10 (medium)

Details

Published Mar 26, 2025
Updated: Mar 27, 2025
CWE ID 918

Summary

CVE-2024-13411 is a Server-Side Request Forgery (SSRF) vulnerability affecting the Zapier for WordPress plugin for WordPress. This issue, present in all versions up to 1.5.1, allows authenticated attackers with Subscriber-level access and above to send malicious requests. As a result, they can make web requests to arbitrary locations, initiating queries and modifications to data from internal services, posing a significant risk to sensitive information.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share