CVE-2024-13446

CVSS 3.1 Score 9.8 of 10 (high)

Details

Published Mar 12, 2025
Updated: Apr 2, 2025
CWE ID 288

Summary

CVE-2024-13446: The Workreap plugin for WordPress, used in versions up to 3.2.5, suffers from a privilege escalation vulnerability. Attackers can exploit this issue through account takeover, either by logging in as an arbitrary user using known email addresses or by changing a user's password, including that of administrators. This can give unauthorized access to the affected accounts. A partial fix was implemented in version 3.2.5.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share