CVE-2024-7425

CVSS 3.1 Score 7.2 of 10 (high)

Details

Published Feb 7, 2025
Updated: Feb 11, 2025
CWE ID 94

Summary

CVE-2024-7425: WP ALL Export Pro plugin for WordPress contains a vulnerability that enables authenticated attackers with Shop Manager-level access or higher to manipulate data and escalate privileges. This flaw, present in all versions up to 1.9.1, stems from insufficient user input validation and sanitization. The attacker can exploit this issue to alter crucial options, including the default role for registration, and even allow unauthorized user registration, leading to administrative access and potential site takeover.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share