Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2024-13420

Опубликовано: 02 мая 2025
Источник: nvd
CVSS3: 4.3
EPSS Низкий

Описание

Multiple plugins and/or themes for WordPress are vulnerable to unauthorized access due to a missing capability check on several AJAX actions like 'gsf_reset_section_options', 'gsf_reset_section_options', 'gsf_create_preset_options' and more in various versions. This makes it possible for authenticated attackers, with Subscriber-level access and above, to reset and modify some of the plugin/theme settings. This issue was escalated to Envato over two months from the date of this disclosure and the issues, while partially patched, are still vulnerable.

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:g5plus:april:*:*:*:*:*:wordpress:*:*
Версия до 5.1 (включая)
cpe:2.3:a:g5plus:auteur:*:*:*:*:*:wordpress:*:*
Версия до 7.1 (включая)
cpe:2.3:a:g5plus:benaa:*:*:*:*:*:wordpress:*:*
Версия до 4.0.0 (включая)
cpe:2.3:a:g5plus:beyot:*:*:*:*:*:wordpress:*:*
Версия до 6.0.6 (включая)

EPSS

Процентиль: 18%
0.00056
Низкий

4.3 Medium

CVSS3

Дефекты

CWE-94
CWE-862

Связанные уязвимости

CVSS3: 4.3
github
9 месяцев назад

Multiple plugins and/or themes for WordPress are vulnerable to unauthorized access due to a missing capability check on several AJAX actions like 'gsf_reset_section_options', 'gsf_reset_section_options', 'gsf_create_preset_options' and more in various versions. This makes it possible for authenticated attackers, with Subscriber-level access and above, to reset and modify some of the plugin/theme settings. This issue was escalated to Envato over two months from the date of this disclosure and the issues, while partially patched, are still vulnerable.

EPSS

Процентиль: 18%
0.00056
Низкий

4.3 Medium

CVSS3

Дефекты

CWE-94
CWE-862