CVE-2024-13444
CVSS 3.1 Score 6.1 of 10 (medium)
Details
Published Jan 21, 2025
CWE ID 352
Summary
CVE-2024-13444 is a Cross-Site Request Forgery (CSRF) vulnerability affecting the wp-greet plugin in all WordPress versions up to 6.2. This issue stems from inadequate or missing nonce validation in a plugin function. As a result, unauthenticated attackers can manipulate user actions by forging requests, potentially leading to setting modifications and malicious web script injection. To exploit this vulnerability, an attacker must trick a site administrator into performing a specific action, such as clicking on a malicious link.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.