CVE-2024-13651
CVSS 3.1 Score 4.3 of 10 (medium)
Details
Published Feb 1, 2025
CWE ID 862
Summary
CVE-2024-13651: The RapidLoad plugin for WordPress, versions up to 2.4.4, is susceptible to data manipulation due to a lacking capability check in the ajax_deactivate() function. Authenticated attackers with Subscriber-level access or higher can exploit this vulnerability to reset certain plugin settings. This poses a risk to website functionality and security. It is recommended that users upgrade to the latest version of RapidLoad to mitigate this issue.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.