CVE-2024-7429

CVSS V2 None CVSS V3 None
Description
The Zotpress plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the Zotpress_process_accounts_AJAX function in all versions up to, and including, 7.3.12. This makes it possible for authenticated attackers, with Contributor-level access and above, to reset the plugin's settings.
Overview
  • CVE ID
  • CVE-2024-7429
  • Assigner
  • Wordfence
  • Vulnerability Status
  • PUBLISHED
  • Published Version
  • 2024-11-05T09:30:58.286Z
  • Last Modified Date
  • 2024-11-05T14:52:27.537Z
History
Created Old Value New Value Data Type Notes
2024-11-06 13:27:10 Added to TrackCVE