CVE-2024-13495
CVSS 3.1 Score 7.3 of 10 (high)
Details
Published Jan 22, 2025
CWE ID 94
Summary
CVE-2024-13495 is a vulnerability affecting the GamiPress plugin for WordPress. The issue lies in the gamipress_ajax_get_logs() function, which is present in all versions up to and including 7.2.1. Attackers can exploit this vulnerability by executing unvalidated actions, leading to arbitrary shortcode execution. As a result, unauthenticated users are able to run malicious code on vulnerable WordPress sites. This vulnerability poses a significant threat, as it allows attackers to bypass authentication and potentially gain control over the affected site.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.