CVE-2024-13452
CVSS 3.1 Score 6.1 of 10 (medium)
Details
Summary
CVE-2024-13452 is a Cross-Site Request Forgery (CSRF) vulnerability affecting the Contact Form plugin by Supsystic for WordPress. Versions up to and including 1.7.29 are impacted by this issue. The root cause is a lack of proper nonce validation in the saveAsCopy function, enabling unauthenticated attackers to manipulate settings and inject malicious web scripts. They can do this by deceiving site administrators into executing a malicious request, typically through a crafted link. This vulnerability poses a significant risk as it allows attackers to gain control over the affected WordPress site.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.