CVE-2024-12028 — The Friends plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on several REST API endpoints in all versions up to, and including, 3.2.1. This makes it possibl — CVE Database · The Intelligence Room