Unauthorized Access Vulnerability in Multiple WordPress Plugins and Themes
CVE-2024-13420
4.3MEDIUM
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 2 May 2025
What is CVE-2024-13420?
Multiple plugins and themes for WordPress exhibit a security weakness, allowing unauthorized access due to inadequate capability checks on various AJAX actions like 'gsf_reset_section_options' and 'gsf_create_preset_options'. As a result, authenticated users with Subscriber-level access or higher can manipulate sensitive plugin and theme settings. Although some patches have been applied, these vulnerabilities remain partially unresolved, posing a continuous risk to webmasters and users alike.
Affected Version(s)
April Framework * <= 5.1
Auteur Framework * <= 7.1
Benaa Framework * <= 4.0.0