CVE-2024-13522
CVSS 3.1 Score 5.4 of 10 (medium)
Details
Published Feb 18, 2025
Updated: Feb 24, 2025
CWE ID 352
Summary
CVE-2024-13522: The magayo Lottery Results plugin for WordPress, affected up to version 2.0.12, has a Cross-Site Request Forgery (CSRF) vulnerability. The issue stems from inadequate nonce validation on the 'magayo-lottery-results' page, allowing unauthenticated attackers to manipulate settings and introduce malicious scripts. This can be exploited by tricking a site administrator into executing a malicious action, such as clicking on a specially crafted link.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Share