CVE-2024-13639

CVSS 3.1 Score 4.3 of 10 (medium)

Details

Published Feb 13, 2025
Updated: Feb 18, 2025
CWE ID 862

Summary

CVE-2024-13639 is a vulnerability affecting the Read More & Accordion plugin for WordPress. This issue allows authenticated attackers, with Subscriber-level access and above, to delete arbitrary 'read more' posts due to a missing capability check on the expmDeleteData() function. Versions up to and including 3.4.2 are impacted, posing a significant risk to data loss. This vulnerability enables attackers to manipulate post content, making it essential for users to update their plugins to the latest version or consider alternative solutions to mitigate the risk.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share