PT-2024-15823 · WordPress · Wolf – Wordpress Posts Bulk Editor/Manager Professional

Francesco Carlucci

·

Published

2024-02-05

·

Updated

2024-02-13

·

CVE-2024-0791

CVSS v3.1

4.3

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions The WOLF – WordPress Posts Bulk Editor and Manager Professional plugin versions up to, and including, 1.0.8.1
Description The issue is related to a missing capability check on the wpbe create new term, wpbe update tax term, and wpbe delete tax term functions. This allows authenticated attackers with subscriber access or higher to create, delete, or modify taxonomy terms, potentially leading to unauthorized access, modification, or loss of data.
Recommendations For versions up to, and including, 1.0.8.1, update to a version that includes a fix for the missing capability check on the wpbe create new term, wpbe update tax term, and wpbe delete tax term functions. As a temporary workaround, consider restricting access to these functions to prevent unauthorized modifications until a patch is available.

Fix

Missing Authorization

Weakness Enumeration

Related Identifiers

CVE-2024-0791

Affected Products

Wolf – Wordpress Posts Bulk Editor/Manager Professional