CVE-2024-13703

CVSS 3.1 Score 4.3 of 10 (medium)

Details

Published Mar 13, 2025
CWE ID 862

Summary

CVE-2024-13703: A vulnerability impacts the CRM and Lead Management plugin by vcita for WordPress. This issue, occurring in the vcita_ajax_toggle_ae() function, allows authenticated attackers with Subscriber-level access or higher to unauthorizedly modify data. The consequence is the ability to enable and disable plugin widgets, posing a security risk to WordPress sites utilizing the affected plugin version 2.7.1 and below.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share