CVE-2024-13450
CVSS 3.1 Score 6.5 of 10 (medium)
Details
Summary
CVE-2024-13450 is a serious vulnerability affecting the Contact Form plugin by Bit Form for WordPress. Versions 2.17.4 and below are impacted, allowing authenticated attackers with Administrator-level access or higher to execute Server-Side Request Forgeries (SSRF) through the Webhooks integration. This issue enables attackers to make web requests from the vulnerable application to arbitrary locations, potentially leading to information disclosure or modification of internal services. In Multisite environments, the risk is amplified as the vulnerability can be exploited across multiple sites.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.