Description
The Draw Attention plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the ajax_set_featured_image function in versions up to, and including, 2.0.11. This makes it possible for authenticated attackers, with subscriber-level permissions and above, to change the featured image of arbitrary posts with an image that exists in the media library.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2023-34222 | The Draw Attention plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the ajax_set_featured_image function in versions up to, and including, 2.0.11. This makes it possible for authenticated attackers, with subscriber-level permissions and above, to change the featured image of arbitrary posts with an image that exists in the media library. |
References
History
Wed, 08 Apr 2026 17:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Draw Attention <= 2.0.11 - Missing Authorization to Arbitrary Post Featured Image Modification | |
| Weaknesses | CWE-862 |
Sat, 21 Dec 2024 00:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Status: PUBLISHED
Assigner: Wordfence
Published:
Updated: 2026-04-08T16:37:36.923Z
Reserved: 2023-05-17T16:02:05.108Z
Link: CVE-2023-2764
Updated: 2024-08-02T06:33:05.391Z
Status : Modified
Published: 2023-06-09T06:16:11.573
Modified: 2026-04-08T17:16:57.403
Link: CVE-2023-2764
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD