CVE-2024-2538
Last modified
CVE-2024-2538 is a medium-severity vulnerability rated 4.3/10 on the CVSS scale. The Permalink Manager Lite plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'ajax_save_permalink' function in all versions up to, and including, 2.4.3.1. This makes it possible for authenticated attackers, with author access and above, to modify the permalinks of arbitrary posts.. EPSS estimates a 0.57% chance of exploitation in the next 30 days.
Description
The Permalink Manager Lite plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'ajax_save_permalink' function in all versions up to, and including, 2.4.3.1. This makes it possible for authenticated attackers, with author access and above, to modify the permalinks of arbitrary posts.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Permalink Manager Lite Project | Permalink Manager Lite | < 2.4.3.2 |
References
- https://gist.github.com/Xib3rR4dAr/b1eec00e844932c6f2f30a63024b404eExploit, Third Party Advisory
- https://gist.github.com/Xib3rR4dAr/b1eec00e844932c6f2f30a63024b404eExploit, Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2024-2538?
How severe is CVE-2024-2538?
How do I fix CVE-2024-2538?
How Strix Helps
- Uncovering a hidden BOLA in Appsmith's snapshot logicStrix autonomously discovered a BOLA/IDOR vulnerability in Appsmith's snapshot deletion path.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2024
- CVE-2024-25366Buffer Overflow vulnerability in mz-automation.de libiec6185…6.2
- CVE-2024-25369A reflected Cross-Site Scripting (XSS) vulnerability in FUEL…5.4
- CVE-2024-2537Improper Control of Dynamically-Managed Code Resources vulne…9.8
- CVE-2024-25371Gramine before a390e33e16ed374a40de2344562a937f289be2e1 suff…7.5
- CVE-2024-25373Tenda AC10V4.0 V16.03.10.20 was discovered to contain a stac…4.6
- CVE-2024-25376An issue discovered in Thesycon Software Solutions Gmbh & Co…7.8
- CVE-2024-25381There is a Stored XSS Vulnerability in Emlog Pro 2.2.8 Artic…6.1
- CVE-2024-25385An issue in flvmeta v.1.2.2 allows a local attacker to cause…6.2
- CVE-2024-25386Directory Traversal vulnerability in DICOM® Connectivity Fra…8.8
- CVE-2024-25388drivers/wlan/wlan_mgmt,c in RT-Thread through 5.0.2 has an i…8.4
- CVE-2024-25389RT-Thread through 5.0.2 generates random numbers with a weak…7.5
- CVE-2024-2539The Elementor Addons by Livemesh plugin for WordPress is vul…5.4
Are you affected by CVE-2024-2538?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
