CVE-2024-13523
CVSS 3.1 Score 5.4 of 10 (medium)
Details
Summary
CVE-2024-13523 is a Cross-Site Request Forgery (CSRF) vulnerability affecting the MemorialDay plugin for WordPress. Versions up to 1.0.4 are susceptible to this issue. The root cause is the lack of proper nonce validation on a plugin function, allowing unauthenticated attackers to update settings and inject malicious web scripts. To exploit this, an attacker must trick a site administrator into performing a specific action, such as clicking a malicious link. This vulnerability poses a significant risk to WordPress sites using the MemorialDay plugin and should be addressed promptly by upgrading to a patched version.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.