CVE-2024-13580
CVSS 3.1 Score 4.3 of 10 (medium)
Details
Summary
CVE-2024-13580 is a vulnerability affecting the XV Random Quotes WordPress plugin before version 1.41. This issue allows attackers to manipulate plugin settings by performing a Cross-Site Request Forgery (CSRF) attack on logged-in admin users. The plugin fails to implement CSRF protection, making it possible for an attacker to trick the admin into making unwanted changes to the plugin settings. Successful exploitation could lead to severe consequences, including unauthorized modifications or complete plugin takeover. It is recommended to update the plugin to the latest version to mitigate this risk.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Vendors
- WordPress