PT-2024-36403 · WordPress · Wordpress Header Builder Plugin
Lucio Sá
·
Published
2024-06-12
·
Updated
2024-06-13
·
CVE-2024-5468
CVSS v3.1
6.5
Medium
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L |
Name of the Vulnerable Software and Affected Versions
WordPress Header Builder Plugin – Pearl versions up to, and including, 1.3.7
Description
The issue is related to unauthorized site option deletion due to missing validation and capability checks on the
stm hb delete() function. This allows unauthenticated attackers to delete arbitrary options, potentially leading to a denial of service attack on a site.Recommendations
For versions up to, and including, 1.3.7, update to a version that includes the necessary validation and capability checks for the
stm hb delete() function to prevent unauthorized site option deletion.Fix
Missing Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Wordpress Header Builder Plugin