CVE-2024-13710

CVSS 3.1 Score 4.3 of 10 (medium)

Details

Published Mar 25, 2025
Updated: Mar 27, 2025
CWE ID 352

Summary

CVE-2024-13710 is a Cross-Site Request Forgery (CSRF) vulnerability affecting the Estatebud – Properties & Listings plugin for WordPress. Versions up to and including 5.5.0 are susceptible to this issue. The vulnerability arises due to incorrect or missing nonce validation on the plugin's 'estatebud_settings' page. As a result, unauthenticated attackers can manipulate the plugin's settings by tricking administrators into performing a malicious action, like clicking on a malicious link. This could potentially lead to serious implications, making it crucial for users to update their plugin to a patched version immediately.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share