CVE-2024-12402 | themescoder Themes Coder Plugin up to 1.3.4 on WordPress update_user_profile authentication bypass
A vulnerability was found in themescoder Themes Coder Plugin up to 1.3.4 on WordPress. It has been rated as critical. Affected by this issue is the function update_user_profile. The manipulation leads to authentication bypass using alternate channel.
This vulnerability is handled as CVE-2024-12402. The attack may be launched remotely. There is no exploit available.
It is recommended to upgrade the affected component.