CVE-2024-13523

CVSS 3.1 Score 5.4 of 10 (medium)

Details

Published Feb 18, 2025
Updated: Feb 21, 2025
CWE ID 352

Summary

CVE-2024-13523 is a Cross-Site Request Forgery (CSRF) vulnerability affecting the MemorialDay plugin for WordPress. Versions up to 1.0.4 are susceptible to this issue. The root cause is the lack of proper nonce validation on a plugin function, allowing unauthenticated attackers to update settings and inject malicious web scripts. To exploit this, an attacker must trick a site administrator into performing a specific action, such as clicking a malicious link. This vulnerability poses a significant risk to WordPress sites using the MemorialDay plugin and should be addressed promptly by upgrading to a patched version.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share