As immediate action, update the affected plugin. If you're unable to do so, ask your hosting provider or web developer for help.
CVE-2024-13710 is likely a partial duplicate of this issue.
While this vulnerability can be initiated by the role shown in "Required Privilege", successful exploitation requires a privileged user to perform an action — such as clicking a malicious link, visiting a crafted page, or submitting a form.
Logged-in users can be tricked into performing actions they didn't intend, like changing passwords or making purchases.
CVSS score is a way to evaluate and rank reported vulnerabilities in a standardized and repeatable way but which is not ideal for WordPress.
This security issue has a low severity impact and is unlikely to be exploited.
17 Dec, 2024