PT-2024-36403 · WordPress · Wordpress Header Builder Plugin

Lucio Sá

·

Published

2024-06-12

·

Updated

2024-06-13

·

CVE-2024-5468

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L
Name of the Vulnerable Software and Affected Versions WordPress Header Builder Plugin – Pearl versions up to, and including, 1.3.7
Description The issue is related to unauthorized site option deletion due to missing validation and capability checks on the stm hb delete() function. This allows unauthenticated attackers to delete arbitrary options, potentially leading to a denial of service attack on a site.
Recommendations For versions up to, and including, 1.3.7, update to a version that includes the necessary validation and capability checks for the stm hb delete() function to prevent unauthorized site option deletion.

Fix

Missing Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2024-5468

Affected Products

Wordpress Header Builder Plugin