CVE-2024-13412 - CozyStay WordPress Unauthenticated Remote Code Execution
CVE ID : CVE-2024-13412
Published : March 19, 2025, 7:15 a.m. | 4 hours, 9 minutes ago
Description : The CozyStay theme for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the ajax_handler function in all versions up to, and including, 1.7.0. This makes it possible for unauthenticated attackers to execute arbitrary actions.
Severity: 7.5 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
Published : March 19, 2025, 7:15 a.m. | 4 hours, 9 minutes ago
Description : The CozyStay theme for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the ajax_handler function in all versions up to, and including, 1.7.0. This makes it possible for unauthenticated attackers to execute arbitrary actions.
Severity: 7.5 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...