CVE-2024-13710
CVSS 3.1 Score 4.3 of 10 (medium)
Details
Summary
CVE-2024-13710 is a Cross-Site Request Forgery (CSRF) vulnerability affecting the Estatebud – Properties & Listings plugin for WordPress. Versions up to and including 5.5.0 are susceptible to this issue. The vulnerability arises due to incorrect or missing nonce validation on the plugin's 'estatebud_settings' page. As a result, unauthenticated attackers can manipulate the plugin's settings by tricking administrators into performing a malicious action, like clicking on a malicious link. This could potentially lead to serious implications, making it crucial for users to update their plugin to a patched version immediately.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.