PT-2025-3734 · WordPress · The Social Rocket – Social Sharing Plugin

Brokenac Ignore

+1

·

Published

2025-01-07

·

Updated

2025-01-07

·

CVE-2024-9697

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions The Social Rocket – Social Sharing Plugin versions up to, and including, 1.3.4
Description The issue allows authenticated attackers with Subscriber-level access and above to update the plugin's settings due to a missing capability check on the tweet settings save() and tweet settings update() functions. This enables unauthorized modification of data.
Recommendations For versions up to, and including, 1.3.4, consider disabling the tweet settings save() and tweet settings update() functions until a patch is available to prevent unauthorized updates to the plugin's settings. Restrict access to the plugin's settings to minimize the risk of exploitation.

Fix

Missing Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2024-9697

Affected Products

The Social Rocket – Social Sharing Plugin