7.5
CVSSv3

CVE-2024-13412

CVSSv4: NA | CVSSv3: 7.5 | CVSSv2: NA | VMScore: 850 | EPSS: 0.00061 | KEV: Not Included
Published: 19/03/2025 Updated: 19/03/2025

Vulnerability Summary

Unauthenticated Data Modification Vulnerability in CozyStay WordPress Theme 1.7.0

The CozyStay WordPress theme contains a security vulnerability in its ajax_handler function across all versions up to and including 1.7.0. This weakness allows unauthenticated attackers to execute arbitrary actions without proper authorization checks, potentially enabling unauthorized data modification.

Vulnerable Product Search on Vulmon Subscribe to Product

loftocean cozystay - hotel booking wordpress theme