CVE-2024-13768
CVSS 3.1 Score 4.3 of 10 (medium)
Details
Summary
CVE-2024-13768 is a Cross-Site Request Forgery (CSRF) vulnerability affecting the CITS Support plugin for WordPress in all versions up to 4.2. This issue is caused by insufficient nonce validation on the cITS_assign_fonts_tab() function, which allows unauthenticated attackers to manipulate font assignments. By tricking a site administrator into taking action, such as clicking on a malicious link, an attacker can delete font assignments, potentially disrupting the functionality of the website. Users are urged to update to the latest plugin version to mitigate this risk.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.