CVE-2024-13643
Last modified
CVE-2024-13643 is a high-severity vulnerability rated 8.8/10 on the CVSS scale. The Zox News - Professional WordPress News & Magazine Theme plugin for WordPress is vulnerable to unauthorized data modification. This vulnerability can lead to privilege escalation and denial of service conditions due to missing capability checks on the backup_options() and reset_options() functions in all versions up to and including 3.17.0. EPSS estimates a 0.59% chance of exploitation in the next 30 days.
Description
The Zox News - Professional WordPress News & Magazine Theme plugin for WordPress is vulnerable to unauthorized data modification. This vulnerability can lead to privilege escalation and denial of service conditions due to missing capability checks on the backup_options() and reset_options() functions in all versions up to and including 3.17.0. This vulnerability allows authenticated attackers with Subscriber-level access and above to update and delete arbitrary option values on the WordPress site. Attackers can exploit this issue to update the default user role for registration to Administrator and enable user registration, thereby gaining administrative access to the vulnerable site. Additionally, they could delete critical options, causing errors that may disrupt the site's functionality and deny service to legitimate users.
Metrics
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Weakness Enumeration
References
Timeline
- Published
- Last Modified
- Status
- Deferred
Frequently Asked Questions
What is CVE-2024-13643?
How severe is CVE-2024-13643?
How do I fix CVE-2024-13643?
How Strix Helps
- Uncovering a hidden BOLA in Appsmith's snapshot logicStrix autonomously discovered a BOLA/IDOR vulnerability in Appsmith's snapshot deletion path.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2024
- CVE-2024-13638The Order Attachments for WooCommerce plugin for WordPress i…7.5
- CVE-2024-13639The Read More & Accordion plugin for WordPress is vulnerable…4.3
- CVE-2024-1364The Elementor Website Builder Pro plugin for WordPress is vu…5.4
- CVE-2024-13640The Print Invoice & Delivery Notes for WooCommerce plugin fo…5.9
- CVE-2024-13641The Return Refund and Exchange For WooCommerce – Return Mana…7.5
- CVE-2024-13642The Stratum – Elementor Widgets plugin for WordPress is vuln…5.4
- CVE-2024-13644The DethemeKit For Elementor plugin for WordPress is vulnera…5.4
- CVE-2024-13645The tagDiv Composer plugin for WordPress is vulnerable to PH…9.8
- CVE-2024-13646The Single-user-chat plugin for WordPress is vulnerable to u…8.1
- CVE-2024-13647The School Management System – SakolaWP plugin for WordPress…4.3
- CVE-2024-13648The Maps for WP plugin for WordPress is vulnerable to Stored…5.4
- CVE-2024-13649The 140+ Widgets | Xpro Addons For Elementor – FREE plugin f…5.4
Are you affected by CVE-2024-13643?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
