CVE-2024-9824

CVSS 3.1 Score 4.3 of 10 (medium)

Details

Published Oct 12, 2024
Updated: Oct 15, 2024
CWE ID 862

Summary

CVE-2024-9824 is a vulnerability affecting the ImagePress – Image Gallery plugin for WordPress. This issue allows authenticated attackers, with Subscriber-level access and above, to bypass capability checks on the 'ip_delete_post' and 'ip_update_post_title' functions. Consequently, attackers can delete arbitrary posts and update post titles, leading to unauthorized modification and potential loss of data for affected WordPress sites using versions up to and including 1.2.2.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share