CVE-2024-13829

CVSS 3.1 Score 5.3 of 10 (medium)

Details

Published Feb 5, 2025
CWE ID 200

Summary

CVE-2024-13829 is a vulnerability affecting the Tripetto plugin for WordPress, which is used for creating contact forms, surveys, and quizzes. The issue lies in the 'attachments.php' file, where sensitive information is exposed, making it accessible to unauthenticated attackers. This vulnerability allows hackers to extract uploaded files and potentially other sensitive data. Versions up to and including 8.0.8 of the plugin are impacted. It is recommended that users immediately update to the latest version or consider disabling the plugin as a temporary measure until a patch is available.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share