PT-2024-36514 · WordPress · Ibtana

Peter Thaleikis

·

Published

2024-06-18

·

Updated

2024-07-05

·

CVE-2024-5541

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions Ibtana – WordPress Website Builder plugin versions up to, and including, 1.2.3.3
Description The issue allows unauthorized modification of data due to a missing capability check on the ibtana visual editor register ajax json endpont function. This enables unauthenticated attackers to update option values for reCAPTCHA keys on the WordPress site, potentially bypassing reCAPTCHA on the site.
Recommendations For versions up to, and including, 1.2.3.3, as a temporary workaround, consider disabling the ibtana visual editor register ajax json endpont function until a patch is available. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Missing Authorization

Weakness Enumeration

Related Identifiers

CVE-2024-5541

Affected Products

Ibtana