CVE-2024-13518
CVSS 3.1 Score 4.3 of 10 (medium)
Details
Published Mar 1, 2025
CWE ID 352
Summary
CVE-2024-13518 is a newly disclosed vulnerability affecting the Simple:Press Forum plugin used in WordPress sites. The issue lies in the 'sp_save_edited_post' function, where nonce validation is either missing or incorrect. This defect opens the door for Cross-Site Request Forgery (CSRF) attacks, allowing unauthenticated adversaries to manipulate forum posts. The vulnerability is present in all versions up to and including 6.10.11, posing a significant risk to sites running this plugin unless patched promptly.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.