Unauthorized Modification of Data Vulnerability in Editorial Assistant Plugin
CVE-2024-9626
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 26 October 2024
What is CVE-2024-9626?
The Editorial Assistant by Sovrn plugin for WordPress suffers from a security issue that allows authenticated users with subscriber-level access and above to exploit the 'ajax_zemanta_set_featured_image' function. This vulnerability arises from a lack of necessary capability checks, enabling attackers to upload various types of files, including images and documents, as well as set featured images on posts. The absence of proper verification increases the risk of unauthorized data manipulation and potential damage to website integrity.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
Editorial Assistant by Sovrn * <= 1.3.3
References
CVSS V3.1
Timeline
Vulnerability published