CVE-2024-7424
Last modified
CVE-2024-7424 is a medium-severity vulnerability rated 5.4/10 on the CVSS scale. The Multiple Page Generator Plugin – MPG plugin for WordPress is vulnerable to unauthorized modification of and access to data due to a missing capability check on several functions in all versions up to, and including, 4.0.1. This makes it possible for authenticated attackers, with Subscriber-level access and above, to invoke those functions intended for admin use resulting in subscribers being able to upload csv files and view the contents of MPG projects.. EPSS estimates a 0.32% chance of exploitation in the next 30 days.
Description
The Multiple Page Generator Plugin – MPG plugin for WordPress is vulnerable to unauthorized modification of and access to data due to a missing capability check on several functions in all versions up to, and including, 4.0.1. This makes it possible for authenticated attackers, with Subscriber-level access and above, to invoke those functions intended for admin use resulting in subscribers being able to upload csv files and view the contents of MPG projects.
Metrics
Weakness Enumeration
References
Timeline
- Published
- Last Modified
- Status
- Deferred
Frequently Asked Questions
What is CVE-2024-7424?
How severe is CVE-2024-7424?
How do I fix CVE-2024-7424?
How Strix Helps
- Uncovering a hidden BOLA in Appsmith's snapshot logicStrix autonomously discovered a BOLA/IDOR vulnerability in Appsmith's snapshot deletion path.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2024
- CVE-2024-7418The The Post Grid – Shortcode, Gutenberg Blocks and Elemento…4.3
- CVE-2024-7419The WP ALL Export Pro plugin for WordPress is vulnerable to …8.8
- CVE-2024-7420The Insert PHP Code Snippet plugin for WordPress is vulnerab…6.5
- CVE-2024-7421An information exposure in Devolutions Remote Desktop Manage…5.5
- CVE-2024-7422The Theme My Login plugin for WordPress is vulnerable to Cro…4.3
- CVE-2024-7423The Stream plugin for WordPress is vulnerable to Cross-Site …8.8
- CVE-2024-7425The WP ALL Export Pro plugin for WordPress is vulnerable to …7.2
- CVE-2024-7426The Community by PeepSo – Social Network, Membership, Regist…5.3
- CVE-2024-7427Improper Neutralization of Input During Web Page Generation …4.8
- CVE-2024-7428URL Redirection to Untrusted Site ('Open Redirect') vulnerab…4.8
- CVE-2024-7429The Zotpress plugin for WordPress is vulnerable to unauthori…4.3
- CVE-2024-7432The Unseen Blog theme for WordPress is vulnerable to PHP Obj…8.8
Are you affected by CVE-2024-7424?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
