๐Ÿ” CVE Alert

CVE-2024-12028

MEDIUM 5.3

Friends <= 3.2.1 - Missing Authorization

CVSS Score
5.3
EPSS Score
0.0%
EPSS Percentile
0th

The Friends plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on several REST API endpoints in all versions up to, and including, 3.2.1. This makes it possible for unauthenticated attackers to send arbitrary friend requests on behalf of another website, accept the friend request for the targeted website, and then communicate with the site as an accepted friend.

CWE CWE-862
Vendor akirk
Product friends
Published Dec 6, 2024
Last Updated Apr 8, 2026
Stay Ahead of the Next One

Get instant alerts for akirk friends

Be the first to know when new medium vulnerabilities affecting akirk friends are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability

Affected Versions

akirk / Friends
0 โ‰ค 3.2.1

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
wordfence.com: https://www.wordfence.com/threat-intel/vulnerabilities/id/980b16d4-3c4a-4ed1-af46-f39f3ec6dd19?source=cve wordpress.org: https://wordpress.org/plugins/friends/#developers plugins.trac.wordpress.org: https://plugins.trac.wordpress.org/changeset?sfp_email=&sfph_mail=&reponame=&new=3203812%40friends%2Ftrunk&old=3199284%40friends%2Ftrunk&sfp_email=&sfph_mail=

Credits

Colin Xu