CVE-2024-13529

CVSS 3.1 Score 6.5 of 10 (medium)

Details

Published Feb 4, 2025
CWE ID 862

Summary

CVE-2024-13529 is a vulnerability affecting the SocialV - Social Network and Community BuddyPress Theme for WordPress. This issue arises from the lack of capability checks on the 'socialv_send_download_file' function in all versions up to 2.0.15. As a result, authenticated attackers with Subscriber-level access and above can exploit this vulnerability to gain unauthorized access to arbitrary files residing on the targeted system. This poses a significant risk to the confidentiality and integrity of data stored on vulnerable WordPress installations. It is highly recommended that users upgrade to the latest version of the theme as soon as possible to mitigate this vulnerability.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share