PT-2024-26535 · WordPress · The Social Link Pages

Lucio Sá

·

Published

2024-06-03

·

Updated

2024-06-07

·

CVE-2024-3555

CVSS v3.1

7.2

High

VectorAV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions The Social Link Pages: link-in-bio landing pages for your social media profiles plugin for WordPress versions up to, and including, 1.6.9
Description The issue is related to a missing capability check on the import link pages() function, allowing unauthenticated attackers to inject arbitrary pages and malicious web scripts. This enables unauthorized access to the system.
Recommendations For versions up to, and including, 1.6.9, consider disabling the import link pages() function until a patch is available to prevent unauthorized access and arbitrary page injection. Restrict access to sensitive areas of the plugin to minimize the risk of exploitation. Update to a version later than 1.6.9 when available.

Fix

Missing Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2024-3555

Affected Products

The Social Link Pages