CVE-2025-24652
CVSS 3.1 Score 5.4 of 10 (medium)
Details
Published Jan 24, 2025
CWE ID 862
Summary
CVE-2025-24652 is a Missing Authorization vulnerability affecting the WP Duplicate – WordPress Migration Plugin from versions n/a through 1.1.6. An attacker can exploit incorrectly configured access control security levels, gaining unauthorized access and potentially executing malicious actions on a WordPress site. This issue poses a significant risk to websites using the plugin and highlights the importance of maintaining up-to-date security measures.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.