Description
The LadiApp plugn for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the init_endpoint() function hooked via 'init' in versions up to, and including, 4.3. This makes it possible for unauthenticated attackers to modify a variety of settings. An attacker can directly modify the 'ladipage_key' which enables them to create new posts on the website and inject malicious web scripts.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2023-54578 | The LadiApp plugn for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the init_endpoint() function hooked via 'init' in versions up to, and including, 4.3. This makes it possible for unauthenticated attackers to modify a variety of settings. An attacker can directly modify the 'ladipage_key' which enables them to create new posts on the website and inject malicious web scripts. |
References
History
Mon, 19 Aug 2024 18:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Binhnguyenplus
Binhnguyenplus ladiapp |
|
| CPEs | cpe:2.3:a:binhnguyenplus:ladiapp:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Binhnguyenplus
Binhnguyenplus ladiapp |
|
| Metrics |
ssvc
|
Sat, 17 Aug 2024 07:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The LadiApp plugn for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the init_endpoint() function hooked via 'init' in versions up to, and including, 4.3. This makes it possible for unauthenticated attackers to modify a variety of settings. An attacker can directly modify the 'ladipage_key' which enables them to create new posts on the website and inject malicious web scripts. | |
| Title | LadiApp: Landing Page, PopupX, Marketing Automation, Affiliate Marketing… <= 4.3 - Missing Authorization via init_endpoint | |
| Weaknesses | CWE-862 | |
| References |
|
|
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: Wordfence
Published:
Updated: 2026-04-08T16:59:11.401Z
Reserved: 2023-09-01T21:43:49.588Z
Link: CVE-2023-4730
Updated: 2024-08-19T17:39:13.000Z
Status : Deferred
Published: 2024-08-17T08:15:06.297
Modified: 2026-04-15T00:35:42.020
Link: CVE-2023-4730
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD