MEDIUM
Zotpress <= 7.3.12 - Missing Authorization
Published Nov 5, 2024
4.3
MEDIUMCVSS 3.1
EPSS 0.36%
Description
The Zotpress plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the Zotpress_process_accounts_AJAX function in all versions up to, and including, 7.3.12. This makes it possible for authenticated attackers, with Contributor-level access and above, to reset the plugin's settings.
Affected products
-
- Version 0StatusaffectedConstraints<=7.3.12
- Version
- < 7.3.13
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (2)
References (4)
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2024-48353 Advisory
- https://plugins.trac.wordpress.org/browser/zotpress/trunk/lib/admin/admin.php#L40 Product
- https://plugins.trac.wordpress.org/changeset/3153348/zotpress/trunk/lib/admin/admin.php Patch
- https://www.wordfence.com/threat-intel/vulnerabilities/id/1f38676b-270f-4b0f-bc98-a14a26b86a50?source=cve Third Party Advisory
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner Wordfence
Published Nov 5, 2024
Updated Apr 8, 2026
Reserved Aug 2, 2024
Link CVE-2024-7429
CISA Vulnrichment
Updated Nov 5, 2024
ENISA EUVD
EUVD-2024-48353 Assigner Wordfence
Published Nov 5, 2024
Updated Apr 8, 2026
Exploited since n/a
Link EUVD-2024-48353