The Hash Elements plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the hash_elements_get_posts_title_by_id() function in all versions up to, and including, 1.4.7. This makes it possible for unauthenticated attackers to retrieve draft post titles that should not be accessible to unauthenticated users.
Metrics
Affected Vendors & Products
References
History
Wed, 13 Nov 2024 19:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Hashthemes
Hashthemes hash Elements |
|
CPEs | cpe:2.3:a:hashthemes:hash_elements:*:*:*:*:*:*:*:* | |
Vendors & Products |
Hashthemes
Hashthemes hash Elements |
|
Metrics |
ssvc
|
Wed, 13 Nov 2024 03:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | The Hash Elements plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the hash_elements_get_posts_title_by_id() function in all versions up to, and including, 1.4.7. This makes it possible for unauthenticated attackers to retrieve draft post titles that should not be accessible to unauthenticated users. | |
Title | Hash Elements <= 1.4.7 - Missing Authorization to Unauthenticated Draft Post Title Exposure | |
Weaknesses | CWE-862 | |
References |
| |
Metrics |
cvssV3_1
|
MITRE
Status: PUBLISHED
Assigner: Wordfence
Published: 2024-11-13T03:20:05.820Z
Updated: 2024-11-13T18:40:41.161Z
Reserved: 2024-11-04T16:41:36.183Z
Link: CVE-2024-10802
Vulnrichment
Updated: 2024-11-13T18:40:33.319Z
NVD
Status : Awaiting Analysis
Published: 2024-11-13T04:15:04.087
Modified: 2024-11-13T17:01:16.850
Link: CVE-2024-10802
Redhat
No data.