CVE-2024-5030
CVSS 3.1 Score 7.1 of 10 (high)
Details
Published Nov 18, 2024
CWE ID 125
Summary
CVE-2024-5030 is a vulnerability affecting the CM Table Of Contents WordPress plugin before version 1.2.3. This issue lacks Cross-Site Request Forgery (CSRF) protection, making it susceptible to attacks. Malicious actors can exploit this vulnerability to manipulate an admin user into resetting plugin settings via a maliciously crafted link or form submission. This could potentially lead to significant changes within the WordPress environment. It is strongly recommended that users update to the latest plugin version to mitigate the risk of such attacks.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Products
- Linux Kernel
Affected Vendors
- LINUX