Unauthorized Data Modification in Altair WordPress Theme
CVE-2024-12922
9.8CRITICAL
What is CVE-2024-12922?
The Altair theme for WordPress is susceptible to unauthorized data modification due to a lack of capability checks within its functions.php file. This vulnerability can be exploited by unauthenticated attackers, enabling them to alter a variety of options on the WordPress site. For instance, attackers may change the registration settings to grant themselves administrative privileges, drastically compromising site security and allowing for potential takeover of the site.
Affected Version(s)
Altair * <= 5.2.4