CVE-2024-13307 | Reales WP Plugin up to 2.1.2 on WordPress authorization
A vulnerability, which was classified as critical, was found in Reales WP Plugin up to 2.1.2 on WordPress. Affected is the function reales_delete_file/reales_delete_file_plans/reales_add_to_favourites/reales_remove_from_favourites. The manipulation leads to missing authorization.
This vulnerability is traded as CVE-2024-13307. It is possible to launch the attack remotely. There is no exploit available.