Unauthorized Data Modification in SKT Page Builder Plugin for WordPress
CVE-2024-1337
4.3MEDIUM
What is CVE-2024-1337?
The SKT Page Builder plugin for WordPress is susceptible to unauthorized data modifications due to an oversight in access controls within the 'saveSktbuilderPageData' function. This flaw affects all versions up to and including 4.1, enabling authenticated users, including those with subscriber privileges, to inject malicious content into website pages. By exploiting this vulnerability, attackers can potentially manipulate crucial site data, compromising the integrity and security of the affected WordPress installations.
Affected Version(s)
SKT Page Builder * <= 4.1