Stored Cross-Site Scripting Vulnerability in Puzzles WP Magazine Theme by ThemeForest
CVE-2024-13769

5.4MEDIUM

What is CVE-2024-13769?

The Puzzles WP Magazine / Review with Store WordPress Theme contains a Stored Cross-Site Scripting vulnerability due to insufficient capability checks on the 'theme_options_ajax_post_action' AJAX action. This flaw exists in all versions up to and including 4.2.4, allowing authenticated users with Subscriber-level access and higher to manipulate the plugin settings and potentially inject malicious scripts. With the developer's decision to remove the affected theme from the repository, users are strongly advised to find alternative solutions to safeguard their sites against this vulnerability.

Affected Version(s)

Puzzles | WP Magazine / Review with Store WordPress Theme + RTL * <= 4.2.4

References

CVSS V3.1

Score:
5.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Lucio Sá
.