Unauthorized Data Modification in Altair WordPress Theme
CVE-2024-12922

9.8CRITICAL

Key Information:

Vendor

WordPress

Status
Vendor
CVE Published:
19 March 2025

What is CVE-2024-12922?

The Altair theme for WordPress is susceptible to unauthorized data modification due to a lack of capability checks within its functions.php file. This vulnerability can be exploited by unauthenticated attackers, enabling them to alter a variety of options on the WordPress site. For instance, attackers may change the registration settings to grant themselves administrative privileges, drastically compromising site security and allowing for potential takeover of the site.

Affected Version(s)

Altair * <= 5.2.4

References

CVSS V3.1

Score:
9.8
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Tonn
.
CVE-2024-12922 : Unauthorized Data Modification in Altair WordPress Theme