CVE-2024-1649
CVSS 3.1 Score 4.3 of 10 (medium)
Details
Published Feb 27, 2024
Updated: Jan 7, 2025
CWE ID 862
Summary
CVE-2024-1649 is a vulnerability affecting the Categorify plugin used in WordPress sites. The issue lies in the lack of capability checks on the function 'categorifyAjaxDeleteCategory', which is present in all versions up to 1.0.7.4. Consequently, authenticated attackers with subscriber-level access or higher can exploit this vulnerability to delete categories unauthorizedly. This vulnerability poses a potential risk to WordPress sites using the Categorify plugin, making it essential for users to update to a patched version as soon as possible.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Share