PT-2024-24612 · WordPress · Zita Elementor Site Library
Lucio Sá
·
Published
2024-06-25
·
Updated
2024-06-25
·
CVE-2024-3249
CVSS v3.1
4.3
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Zita Elementor Site Library plugin for WordPress versions up to, and including, 1.6.2
Description
The issue allows authenticated attackers with subscriber-level access and above to modify data without proper authorization due to a missing capability check on several functions, including
import xml data, xml data import, import option data, import widgets, and import customizer settings. This enables attackers to create pages, update certain options such as WooCommerce page titles and Elementor settings, import widgets, and update the plugin's customizer settings and the WordPress custom CSS.Recommendations
For versions up to, and including, 1.6.2, consider updating to a version where this vulnerability is fully fixed, as version 1.6.2 only partially addresses the issue.
As a temporary workaround, consider restricting access to the
import xml data, xml data import, import option data, import widgets, and import customizer settings functions until a fully patched version is available.Fix
Missing Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Zita Elementor Site Library