PT-2024-30172 · WordPress · White Label Cms

Krzysztof Zając

·

Published

2024-05-10

·

Updated

2024-05-14

·

CVE-2024-4280

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions White Label CMS plugin for WordPress versions prior to 2.7.4
Description The issue allows unauthorized modification of data due to a missing capability check on the reset plugin function. This makes it possible for unauthenticated attackers to reset plugin settings.
Recommendations For versions up to and including 2.7.3, update to version 2.7.4 or later to resolve the issue.

Fix

Missing Authorization

Weakness Enumeration

Related Identifiers

CVE-2024-4280

Affected Products

White Label Cms