CVE-2024-13741
CVSS 3.1 Score 5.4 of 10 (medium)
Details
Summary
CVE-2024-13741 is a serious vulnerability affecting the ProfileGrid plugin for WordPress. This issue permits authenticated attackers, even those with Subscriber-level access, to perform Limited Server-Side Request Forgery (SSRF) through the pm_upload_image function. The vulnerability enables attackers to send malicious requests to arbitrary locations, potentially leading to image downloads or file existence validation on both local and remote servers. This poses a significant risk for sensitive data exposure or unauthorized access. The vulnerability affects all versions of ProfileGrid up to and including 5.9.4.2. It is strongly recommended that users update to the latest version of the plugin to mitigate this risk.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.