PT-2025-1714 · WordPress · Wp Extended

Lucio Sá

·

Published

2025-01-08

·

Updated

2025-01-17

·

CVE-2024-11916

CVSS v3.1

7.4

High

VectorAV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:L
Name of the Vulnerable Software and Affected Versions The Ultimate WordPress Toolkit – WP Extended plugin for WordPress versions up to, and including, 3.0.11
Description The issue is related to a missing capability check on several functions, allowing authenticated attackers with subscriber-level access and above to import and activate arbitrary code snippets. This enables unauthorized modification and retrieval of data.
Recommendations For versions up to, and including, 3.0.11, update to a version higher than 3.0.11 to resolve the issue. As a temporary workaround, consider restricting access to the plugin's functionality to minimize the risk of exploitation.

Fix

Missing Authorization

XSS

Weakness Enumeration

Related Identifiers

CVE-2024-11916

Affected Products

Wp Extended