CVE-2024-56280

CVSS 3.1 Score 8.8 of 10 (high)

Details

Published Jan 7, 2025
CWE ID 266

Summary

CVE-2024-56280 is a newly disclosed Privilege Escalation vulnerability affecting WPGuppy, a plugin used by Amento Tech Pvt Ltd. The error lies in the incorrect privilege assignment, granting unauthorized access to users. This issue can be exploited to escalate privileges, potentially allowing attackers to gain administrative control on affected WordPress sites. The vulnerability affects WPGuppy versions from n/a through 1.1.0. Users are urged to update to a patched version as soon as possible to mitigate this risk.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share