CVE-2024-11913
Last modified
CVE-2024-11913 is a medium-severity vulnerability rated 5.4/10 on the CVSS scale. The Activity Plus Reloaded for BuddyPress plugin for WordPress is vulnerable to Blind Server-Side Request Forgery in all versions up to, and including, 1.1.1 via the 'ajax_preview_link' function. This makes it possible for authenticated attackers, with Subscriber-level access and above, to make web requests to arbitrary locations originating from the web application and can be used to query and modify information from internal services.. EPSS estimates a 0.23% chance of exploitation in the next 30 days.
Description
The Activity Plus Reloaded for BuddyPress plugin for WordPress is vulnerable to Blind Server-Side Request Forgery in all versions up to, and including, 1.1.1 via the 'ajax_preview_link' function. This makes it possible for authenticated attackers, with Subscriber-level access and above, to make web requests to arbitrary locations originating from the web application and can be used to query and modify information from internal services.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Buddydev | Activity Plus Reloaded For Buddypress | < 1.1.2 |
References
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2024-11913?
How severe is CVE-2024-11913?
How do I fix CVE-2024-11913?
How Strix Helps
- One Click Account Takeover in GranolaHow a notification link broke out of Electron and led to a one-click account takeover.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2024
- CVE-2024-11906The TPG Get Posts plugin for WordPress is vulnerable to Stor…6.4
- CVE-2024-11907The Skyword API Plugin plugin for WordPress is vulnerable to…6.4
- CVE-2024-1191A vulnerability was found in Hyper CdCatalog 2.3.1. It has b…5.5
- CVE-2024-11910The WP Crowdfunding plugin for WordPress is vulnerable to St…5.4
- CVE-2024-11911The WP Crowdfunding plugin for WordPress is vulnerable to un…4.3
- CVE-2024-11912The Travel Booking WordPress Theme theme for WordPress is vu…7.5
- CVE-2024-11914The Gutenberg Blocks and Page Layouts – Attire Blocks plugin…6.4
- CVE-2024-11915The RRAddons for Elementor plugin for WordPress is vulnerabl…4.3
- CVE-2024-11916The The Ultimate WordPress Toolkit – WP Extended plugin for …5.4
- CVE-2024-11917The JobSearch WP Job Board plugin for WordPress is vulnerabl…8.1
- CVE-2024-11918The Image Alt Text plugin for WordPress is vulnerable to una…4.3
- CVE-2024-11919Inappropriate implementation in Intents in Google Chrome on …4.3
Are you affected by CVE-2024-11913?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
