CVE-2025-24652

CVSS 3.1 Score 5.4 of 10 (medium)

Details

Published Jan 24, 2025
CWE ID 862

Summary

CVE-2025-24652 is a Missing Authorization vulnerability affecting the WP Duplicate – WordPress Migration Plugin from versions n/a through 1.1.6. An attacker can exploit incorrectly configured access control security levels, gaining unauthorized access and potentially executing malicious actions on a WordPress site. This issue poses a significant risk to websites using the plugin and highlights the importance of maintaining up-to-date security measures.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share