Unauthorized Modification of Data Vulnerability in White Label CMS for WordPress
CVE-2024-4280
5.3MEDIUM
What is CVE-2024-4280?
The White Label CMS plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the reset_plugin function in all versions up to, and including, 2.7.3. This makes it possible for unauthenticated attackers to reset plugin settings.
Affected Version(s)
White Label CMS * <= 2.7.3