CVE-2024-0248
EazyDocs < 2.4.0 - Subscriber+ Arbitrary Posts Deletion and Document Management
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
1Exploited in Wild
-Decision
Descriptions
The EazyDocs WordPress plugin before 2.4.0 re-introduced CVE-2023-6029 (https://wpscan.com/vulnerability/7a0aaf85-8130-4fd7-8f09-f8edc929597e/) in 2.3.8, allowing any authenticated users, such as subscriber to delete arbitrary posts, as well as add and delete documents/sections. The issue was partially fixed in 2.3.9.
El complemento EazyDocs de WordPress anterior a 2.4.0 reintrodujo CVE-2023-6029 (https://wpscan.com/vulnerability/7a0aaf85-8130-4fd7-8f09-f8edc929597e/) en 2.3.8, lo que permite a cualquier usuario autenticado, como suscriptor para eliminar publicaciones arbitrarias, asà como agregar y eliminar documentos/secciones. El problema se solucionó parcialmente en 2.3.9.
The EazyDocs plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on various functions in versions 2.3.8 to 2.3.9. This makes it possible for authenticated attackers, with subscriber-level access and above, to delete arbitrary posts and add/delete documents and sections.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2023-12-21 CVE Published
- 2024-01-05 CVE Reserved
- 2024-08-01 CVE Updated
- 2024-08-01 First Exploit
- 2024-10-10 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
- CWE-862: Missing Authorization
CAPEC
References (1)
URL | Tag | Source |
---|
URL | Date | SRC |
---|---|---|
https://wpscan.com/vulnerability/faf50bc0-64c5-4ccc-a8ac-e73ed44a74df | 2024-08-01 |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Unknown Search vendor "Unknown" | EazyDocs Search vendor "Unknown" for product "EazyDocs" | >= 2.3.8 < 2.4.0 Search vendor "Unknown" for product "EazyDocs" and version " >= 2.3.8 < 2.4.0" | en |
Affected
|