CVE-2024-0248
MEDIUMDescription
The EazyDocs WordPress plugin before 2.4.0 re-introduced CVE-2023-6029 (https://wpscan.com/vulnerability/7a0aaf85-8130-4fd7-8f09-f8edc929597e/) in 2.3.8, allowing any authenticated users, such as subscriber to delete arbitrary posts, as well as add and delete documents/sections. The issue was partially fixed in 2.3.9.
Is your site exposed to CVE-2024-0248?
Run a free security scan — no signup, results in seconds.
CVSS v3.1 Score
Affected Products
| Vendor | Product |
|---|---|
| spider-themes | eazydocs |
References
Frequently Asked Questions
What is CVE-2024-0248? +
How severe is CVE-2024-0248? +
What products are affected by CVE-2024-0248? +
How do I check if I'm vulnerable to CVE-2024-0248? +
Related Vulnerabilities
The EazyDocs WordPress plugin before 2.3.6 does not have authorization and CSRF checks when handling documents and does not ensure …
The BBP Core – Expand bbPress powered forums with useful features plugin for WordPress is vulnerable to Reflected Cross-Site Scripting …
The EazyDocs WordPress plugin before 2.5.0 does not sanitise and escape some of its settings, which could allow high privilege …