CVE-2024-13913
CVSS 3.1 Score 8.8 of 10 (high)
Details
Summary
CVE-2024-13913: A critical vulnerability affects the InstaWP Connect plugin for WordPress. The issue lies in the absence of proper nonce validation in the '/migrate/templates/main.php' file, leading to Cross-Site Request Forgery (CSRF). Unauthenticated attackers can exploit this vulnerability to perform arbitrary file inclusions and execute PHP code contained in those files. This can result in bypassing access controls, data theft, and code execution, especially for files that are typically considered safe, such as images. All versions up to and including 0.1.0.83 are impacted.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Products
- Connect Plugin