PT-2024-15558 · WordPress · Wptravelly

Francesco Carlucci

·

Published

2024-05-29

·

Updated

2024-05-29

·

CVE-2024-0434

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions WpTravelly plugin for WordPress versions prior to 1.7.2
Description The issue allows unauthorized modification of data due to a missing capability check on the ttbm new place save function. This enables unauthenticated attackers to create and publish new place posts. The function is also vulnerable to CSRF, allowing attackers to perform actions without the user's knowledge.
Recommendations For versions prior to 1.7.2, update to version 1.7.2 or later to resolve the issue. As a temporary workaround, consider disabling the ttbm new place save function until a patch is available. Restrict access to the affected function to minimize the risk of exploitation.

Fix

Improper Access Control

Weakness Enumeration

Related Identifiers

CVE-2024-0434

Affected Products

Wptravelly