CVE-2024-13769
Last modified
CVE-2024-13769 is a medium-severity vulnerability rated 5.4/10 on the CVSS scale. The Puzzles | WP Magazine / Review with Store WordPress Theme + RTL theme for WordPress is vulnerable to Stored Cross-Site Scripting due to a missing capability check on the 'theme_options_ajax_post_action' AJAX action in all versions up to, and including, 4.2.4. This makes it possible for authenticated attackers, with Subscriber-level access and above, to update the plugin's settings and inject malicious web scripts. EPSS estimates a 0.28% chance of exploitation in the next 30 days.
Description
The Puzzles | WP Magazine / Review with Store WordPress Theme + RTL theme for WordPress is vulnerable to Stored Cross-Site Scripting due to a missing capability check on the 'theme_options_ajax_post_action' AJAX action in all versions up to, and including, 4.2.4. This makes it possible for authenticated attackers, with Subscriber-level access and above, to update the plugin's settings and inject malicious web scripts. The developer opted to remove the software from the repository, so an update is not available and it is recommended to find a replacement software.
Metrics
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Themerex | Puzzles | < 4.2.5 |
References
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2024-13769?
How severe is CVE-2024-13769?
How do I fix CVE-2024-13769?
How Strix Helps
- Uncovering a hidden BOLA in Appsmith's snapshot logicStrix autonomously discovered a BOLA/IDOR vulnerability in Appsmith's snapshot deletion path.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2024
- CVE-2024-13757The Master Slider – Responsive Touch Slider plugin for WordP…5.4
- CVE-2024-13758The CP Contact Form with PayPal plugin for WordPress is vuln…6.5
- CVE-2024-13759Local Privilege Escalation in Avira.Spotlight.Service.exe in…7.8
- CVE-2024-1376The Event post plugin for WordPress is vulnerable to unautho…4.3
- CVE-2024-13767The Live2DWebCanvas plugin for WordPress is vulnerable to ar…8.1
- CVE-2024-13768The CITS Support svg, webp Media and TTF,OTF File Upload, Us…4.3
- CVE-2024-1377The Happy Addons for Elementor plugin for WordPress is vulne…5.4
- CVE-2024-13770The Puzzles | WP Magazine / Review with Store WordPress Them…9.8
- CVE-2024-13771The Civi - Job Board & Freelance Marketplace WordPress Theme…5.9
- CVE-2024-13772The Civi - Job Board & Freelance Marketplace WordPress Theme…5.9
- CVE-2024-13773The Civi - Job Board & Freelance Marketplace WordPress Theme…7.5
- CVE-2024-13774The Wishlist for WooCommerce: Multi Wishlists Per Customer p…6.5
Are you affected by CVE-2024-13769?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
