PT-2024-27103 · WordPress · Wp Scraper

Lucio Sá

·

Published

2024-05-22

·

Updated

2024-05-22

·

CVE-2024-3663

CVSS v3.1

4.3

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions WP Scraper plugin for WordPress versions up to, and including, 5.7
Description The issue is related to unauthorized access due to a missing capability check on the wp scraper multi scrape action() function. This allows authenticated attackers with subscriber-level access and above to create arbitrary pages and posts.
Recommendations For WP Scraper plugin for WordPress versions up to, and including, 5.7, consider disabling the wp scraper multi scrape action() function until a patch is available to prevent unauthorized access.

Fix

Missing Authorization

Weakness Enumeration

Related Identifiers

CVE-2024-3663

Affected Products

Wp Scraper