CVE-2024-1650
CVSS 3.1 Score 4.3 of 10 (medium)
Details
Published Feb 27, 2024
Summary
CVE-2024-1650 is a vulnerability affecting the Categorify plugin for WordPress. The issue lies in the lack of capability checks on the function 'categorifyAjaxRenameCategory'. This enables authenticated attackers, with subscriber-level access and above, to manipulate and rename categories unauthorizedly, potentially leading to site misconfiguration or unintended data modification. Versions of the plugin up to, and including, 1.0.7.4 are reportedly vulnerable.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Share