CVE-2024-13829
CVSS 3.1 Score 5.3 of 10 (medium)
Details
Summary
CVE-2024-13829 is a vulnerability affecting the Tripetto plugin for WordPress, which is used for creating contact forms, surveys, and quizzes. The issue lies in the 'attachments.php' file, where sensitive information is exposed, making it accessible to unauthenticated attackers. This vulnerability allows hackers to extract uploaded files and potentially other sensitive data. Versions up to and including 8.0.8 of the plugin are impacted. It is recommended that users immediately update to the latest version or consider disabling the plugin as a temporary measure until a patch is available.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Vendors
- WordPress