CVE-2024-1912
CVSS 3.1 Score 4.3 of 10 (medium)
Details
Published Feb 27, 2024
Updated: Jan 7, 2025
CWE ID 352
Summary
CVE-2024-1912: A critical vulnerability affects the Categorify plugin for WordPress. The issue, present in all versions up to 1.0.7.4, stems from a lack of proper nonce validation in the function categorifyAjaxUpdateFolderPosition. This flaw exposes the plugin to Cross-Site Request Forgery (CSRF) attacks. Unauthenticated assailants can exploit this by tricking administrators into clicking malicious links and manipulate the folder position of categories and even update the metadata of other taxonomies.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.