PT-2024-28362 · WordPress · Swift Framework

Francesco Carlucci

·

Published

2024-05-09

·

Updated

2024-05-14

·

CVE-2024-3915

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions Swift Framework plugin for WordPress versions prior to 2.7.32
Description The issue allows unauthorized modification of data due to a missing capability check on the sf edit directory item() function. This enables unauthenticated attackers to update arbitrary posts with arbitrary content.
Recommendations For versions prior to 2.7.32, update to version 2.7.32 or later to resolve the issue. As a temporary workaround, consider disabling the sf edit directory item() function until a patch is available. Restrict access to the plugin's directory item editing functionality to minimize the risk of exploitation.

Fix

Missing Authorization

Weakness Enumeration

Related Identifiers

CVE-2024-3915

Affected Products

Swift Framework