CVE-2024-13529
CVSS 3.1 Score 6.5 of 10 (medium)
Details
Summary
CVE-2024-13529 is a vulnerability affecting the SocialV - Social Network and Community BuddyPress Theme for WordPress. This issue arises from the lack of capability checks on the 'socialv_send_download_file' function in all versions up to 2.0.15. As a result, authenticated attackers with Subscriber-level access and above can exploit this vulnerability to gain unauthorized access to arbitrary files residing on the targeted system. This poses a significant risk to the confidentiality and integrity of data stored on vulnerable WordPress installations. It is highly recommended that users upgrade to the latest version of the theme as soon as possible to mitigate this vulnerability.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.