The Top Store theme for WordPress is vulnerable to unauthorized arbitrary plugin installation due to a missing capability check on the top_store_install_and_activate_callback() function in all versions up to, and including, 1.5.4. This makes it possible for authenticated attackers, with subscriber-level access and above, to install arbitrary plugins which can contain other exploitable vulnerabilities to elevate privileges and gain remote code execution.
Metrics
Affected Vendors & Products
References
History
Tue, 12 Nov 2024 19:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Themehunk
Themehunk top Store |
|
CPEs | cpe:2.3:a:themehunk:top_store:*:*:*:*:*:*:*:* | |
Vendors & Products |
Themehunk
Themehunk top Store |
|
Metrics |
ssvc
|
Sat, 09 Nov 2024 03:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | The Top Store theme for WordPress is vulnerable to unauthorized arbitrary plugin installation due to a missing capability check on the top_store_install_and_activate_callback() function in all versions up to, and including, 1.5.4. This makes it possible for authenticated attackers, with subscriber-level access and above, to install arbitrary plugins which can contain other exploitable vulnerabilities to elevate privileges and gain remote code execution. | |
Title | Top Store <= 1.5.4 - Authenticated (Subscriber+) Arbitrary Plugin Installation/Activation | |
Weaknesses | CWE-862 | |
References |
| |
Metrics |
cvssV3_1
|
MITRE
Status: PUBLISHED
Assigner: Wordfence
Published: 2024-11-09T03:17:53.611Z
Updated: 2024-11-12T18:44:39.645Z
Reserved: 2024-11-01T11:00:39.468Z
Link: CVE-2024-10673
Vulnrichment
Updated: 2024-11-12T18:44:33.880Z
NVD
Status : Awaiting Analysis
Published: 2024-11-09T04:15:04.363
Modified: 2024-11-12T13:56:24.513
Link: CVE-2024-10673
Redhat
No data.