CVE-2024-13438
CVSS 3.1 Score 4.3 of 10 (medium)
Details
Summary
CVE-2024-13438 is a Cross-Site Request Forgery (CSRF) vulnerability affecting the SpeedSize Image & Video AI-Optimizer plugin for WordPress. Versions up to and including 1.5.1 are impacted by this issue. The root cause lies in the lack of proper nonce validation on the 'speedsize_clear_css_cache_action' function, which enables attackers to clear the plugin's cache through malicious requests. They can accomplish this by tricking a site administrator into performing an action like clicking a link. Unauthenticated attackers can exploit this vulnerability to modify plugin settings or gain access to sensitive information. It is crucial for WordPress users to update their SpeedSize plugin to a version free from this vulnerability to ensure the security of their websites.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.