CVE-2024-13446
CVSS 3.1 Score 9.8 of 10 (high)
Details
Published Mar 12, 2025
Updated: Apr 2, 2025
CWE ID 288
Summary
CVE-2024-13446: The Workreap plugin for WordPress, used in versions up to 3.2.5, suffers from a privilege escalation vulnerability. Attackers can exploit this issue through account takeover, either by logging in as an arbitrary user using known email addresses or by changing a user's password, including that of administrators. This can give unauthorized access to the affected accounts. A partial fix was implemented in version 3.2.5.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.