CVE-2024-3609
CVSS 3.1 Score 4.3 of 10 (medium)
Details
Published May 16, 2024
Updated: May 17, 2024
Summary
CVE-2024-3609: The ReviewX plugin for WordPress, used for multi-criteria rating and reviews with WooCommerce, contains a vulnerability. An attacker with subscriber access or higher can exploit the missing capability check on the reviewx_remove_guest_image function, present in all versions up to 1.6.27, to delete attachments unauthorizedly. This issue poses a risk for data loss.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.