CVE-2024-1912

CVSS 3.1 Score 4.3 of 10 (medium)

Details

Published Feb 27, 2024
Updated: Jan 7, 2025
CWE ID 352

Summary

CVE-2024-1912: A critical vulnerability affects the Categorify plugin for WordPress. The issue, present in all versions up to 1.0.7.4, stems from a lack of proper nonce validation in the function categorifyAjaxUpdateFolderPosition. This flaw exposes the plugin to Cross-Site Request Forgery (CSRF) attacks. Unauthenticated assailants can exploit this by tricking administrators into clicking malicious links and manipulate the folder position of categories and even update the metadata of other taxonomies.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share