CVE-2024-13419
MEDIUMDescription
Multiple plugins and/or themes for WordPress using Smart Framework are vulnerable to Stored Cross-Site Scripting due to a missing capability check on the saveOptions() and importThemeOptions() functions in various versions. This makes it possible for authenticated attackers, with Subscriber-level access and above, to update the plugin's settings which includes custom JavaScript that is enabled site-wide. This issue was escalated to Envato over two months from the date of this disclosure and the issue is still vulnerable.
Is your site exposed to CVE-2024-13419?
Run a free security scan — no signup, results in seconds.
CVSS v3.1 Score
Weakness Type (CWE)
Affected Products
| Vendor | Product |
|---|---|
| g5plus | april |
| g5plus | auteur |
| g5plus | benaa |
| g5plus | beyot |
References
Frequently Asked Questions
What is CVE-2024-13419? +
How severe is CVE-2024-13419? +
What products are affected by CVE-2024-13419? +
How do I check if I'm vulnerable to CVE-2024-13419? +
Related Vulnerabilities
FreeScout is a free self-hosted help desk and shared mailbox. Prior to version 1.8.213, the `load_customer_info` action in `POST /conversation/ajax` …
GLPI is a free asset and IT management software package. Starting in version 0.78 and prior to versions 10.0.25 and …
In affected versions of Octopus Server, permissions were not checked correctly resulting in any authenticated user being able to make …
SOPlanning does not enforce authorization for backup functionalities. An unauthenticated attacker can directly query backup-related endpoints and retrieve backup archives …
Missing authorization in Checkmk <2.5.0p10, <2.4.0p35, <2.3.0p49, and 2.2.0 (EOL) allows an authenticated user lacking the "Edit foreign Reports" permission …
A denial-of-service vulnerability exists in NPort devices because of improper access control on the command port. The command interface does …