Unauthorized Data Modification in SKT Page Builder Plugin for WordPress
CVE-2024-1337
4.3MEDIUM
Summary
The SKT Page Builder plugin for WordPress is susceptible to unauthorized data modifications due to an oversight in access controls within the 'saveSktbuilderPageData' function. This flaw affects all versions up to and including 4.1, enabling authenticated users, including those with subscriber privileges, to inject malicious content into website pages. By exploiting this vulnerability, attackers can potentially manipulate crucial site data, compromising the integrity and security of the affected WordPress installations.
Affected Version(s)
SKT Page Builder * <= 4.1
References
CVSS V3.1
Score:
4.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Francesco Carlucci