Description
The Top Store theme for WordPress is vulnerable to unauthorized arbitrary plugin installation due to a missing capability check on the top_store_install_and_activate_callback() function in all versions up to, and including, 1.5.4. This makes it possible for authenticated attackers, with subscriber-level access and above, to install arbitrary plugins which can contain other exploitable vulnerabilities to elevate privileges and gain remote code execution.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
No advisories yet.
References
History
Tue, 12 Nov 2024 19:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Themehunk
Themehunk top Store |
|
| CPEs | cpe:2.3:a:themehunk:top_store:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Themehunk
Themehunk top Store |
|
| Metrics |
ssvc
|
Sat, 09 Nov 2024 03:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The Top Store theme for WordPress is vulnerable to unauthorized arbitrary plugin installation due to a missing capability check on the top_store_install_and_activate_callback() function in all versions up to, and including, 1.5.4. This makes it possible for authenticated attackers, with subscriber-level access and above, to install arbitrary plugins which can contain other exploitable vulnerabilities to elevate privileges and gain remote code execution. | |
| Title | Top Store <= 1.5.4 - Authenticated (Subscriber+) Arbitrary Plugin Installation/Activation | |
| Weaknesses | CWE-862 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: Wordfence
Published:
Updated: 2026-04-08T17:03:33.174Z
Reserved: 2024-11-01T11:00:39.468Z
Link: CVE-2024-10673
Updated: 2024-11-12T18:44:33.880Z
Status : Deferred
Published: 2024-11-09T04:15:04.363
Modified: 2026-04-15T00:35:42.020
Link: CVE-2024-10673
No data.
OpenCVE Enrichment
No data.
Weaknesses