CVE-2024-13641

CVSS 3.1 Score 7.5 of 10 (high)

Details

Published Feb 14, 2025
Updated: Feb 25, 2025
CWE ID 200

Summary

CVE-2024-13641 is a new vulnerability affecting the Return Management System plugin for WordPress, specifically versions up to 4.4.5. The issue lies in the 'attachment' directory of the plugin, which is vulnerable to Sensitive Information Exposure. Unauthenticated attackers can exploit this vulnerability and extract sensitive data, including file attachments related to order refunds, stored insecurely in the /wp-content/attachment directory. This can lead to potential data breaches, compromising confidential customer information. WordPress users are urged to update the plugin to the latest version to mitigate this risk.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share