PT-2024-18185 · WordPress · 360 Javascript Viewer

Lucio Sá

·

Published

2024-04-09

·

Updated

2024-04-10

·

CVE-2024-1637

CVSS v3.1

4.3

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions 360 Javascript Viewer plugin for WordPress versions prior to 1.7.13
Description The issue allows authenticated attackers with subscriber access or higher to update plugin settings due to a missing capability check and nonce exposure on several AJAX actions.
Recommendations For versions prior to 1.7.13, update to version 1.7.13 or later to resolve the issue.

Fix

Missing Authorization

Weakness Enumeration

Related Identifiers

CVE-2024-1637

Affected Products

360 Javascript Viewer