PT-2025-7345 · WordPress · Raptive Ads

Tieu Pham Trong Nhan

·

Published

2025-02-19

·

Updated

2025-02-25

·

CVE-2024-13364

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions Raptive Ads plugin for WordPress versions up to, and including, 3.6.3
Description The issue is related to a missing capability check on the site ads files reset() and cls file reset() functions. This allows unauthenticated attackers to reset the ad and cls files.
Recommendations For versions up to, and including, 3.6.3, update to a version that includes a fix for the missing capability check on the site ads files reset() and cls file reset() functions. As a temporary workaround, consider disabling the site ads files reset() and cls file reset() functions until a patch is available. Restrict access to the ad and cls files to minimize the risk of exploitation.

Fix

Missing Authorization

Weakness Enumeration

Related Identifiers

CVE-2024-13364

Affected Products

Raptive Ads