CVE-2024-13818

CVSS 3.1 Score 7.5 of 10 (high)

Details

Published Feb 21, 2025
Updated: Feb 25, 2025
CWE ID 532

Summary

CVE-2024-13818 is a vulnerability affecting the Registration Forms plugin for WordPress, specifically versions up to 3.8.3.9. This issue exposes sensitive user information through publicly accessible log files. Unauthenticated attackers can gain access to this data, potentially including usernames, email addresses, and other private details. The vulnerability poses a significant risk to WordPress sites using the affected plugin and requires immediate attention and patching.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share