CVE-2024-49775

CVSS 3.1 Score 9.8 of 10 (high)

Details

Published Dec 16, 2024
CWE ID 122

Summary

CVE-2024-54353 is a newly disclosed vulnerability affecting WPGear Hack-Info, a plugin used for WordPress sites. The issue combines a Cross-Site Request Forgery (CSRF) weakness and Stored Cross-Site Scripting (XSS), allowing unauthenticated attackers to inject malicious scripts into vulnerable sites. This threat targets Hack-Info versions from n/a through 3.17. Attackers can exploit this vulnerability to steal user information, perform unauthorized actions, or even gain full control of affected websites. It is crucial for users to upgrade their WPGear Hack-Info plugin as soon as possible to mitigate this risk.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share