CVE-2024-13553
CVSS 3.1 Score 9.8 of 10 (high)
Details
Published Apr 1, 2025
CWE ID 288
Summary
CVE-2024-13553: The SMS Alert Order Notifications plugin for WordPress, versions up to 3.7.9, is susceptible to privilege escalation through account takeover. This vulnerability arises due to the plugin relying on the Host header to identify playground environments. Consequently, unauthenticated attackers can manipulate the Host header, tricking the plugin into accepting "1234" as the OTP code and granting access to any user account, including administrative ones.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.