Unauthorized Modification of Data Vulnerability in Editorial Assistant Plugin
CVE-2024-9626

4.3MEDIUM

Key Information:

Vendor

WordPress

Vendor
CVE Published:
26 October 2024

What is CVE-2024-9626?

The Editorial Assistant by Sovrn plugin for WordPress suffers from a security issue that allows authenticated users with subscriber-level access and above to exploit the 'ajax_zemanta_set_featured_image' function. This vulnerability arises from a lack of necessary capability checks, enabling attackers to upload various types of files, including images and documents, as well as set featured images on posts. The absence of proper verification increases the risk of unauthorized data manipulation and potential damage to website integrity.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.

Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.

Affected Version(s)

Editorial Assistant by Sovrn * <= 1.3.3

References

CVSS V3.1

Score:
4.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

.