PT-2024-26535 · WordPress · The Social Link Pages
Lucio Sá
·
Published
2024-06-03
·
Updated
2024-06-07
·
CVE-2024-3555
CVSS v3.1
7.2
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
The Social Link Pages: link-in-bio landing pages for your social media profiles plugin for WordPress versions up to, and including, 1.6.9
Description
The issue is related to a missing capability check on the
import link pages() function, allowing unauthenticated attackers to inject arbitrary pages and malicious web scripts. This enables unauthorized access to the system.Recommendations
For versions up to, and including, 1.6.9, consider disabling the
import link pages() function until a patch is available to prevent unauthorized access and arbitrary page injection. Restrict access to sensitive areas of the plugin to minimize the risk of exploitation. Update to a version later than 1.6.9 when available.Fix
Missing Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
The Social Link Pages