Multiple plugins and/or themes for WordPress are vulnerable to unauthorized access due to a missing capability check on several AJAX actions like 'gsf_reset_section_options', 'gsf_reset_section_options', 'gsf_create_preset_options' and more in various versions. This makes it possible for authenticated attackers, with Subscriber-level access and above, to reset and modify some of the plugin/theme settings. This issue was escalated to Envato over two months from the date of this disclosure and the issues, while partially patched, are still vulnerable.
Metrics
Affected Vendors & Products
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-54449 | Multiple plugins and/or themes for WordPress are vulnerable to unauthorized access due to a missing capability check on several AJAX actions like 'gsf_reset_section_options', 'gsf_reset_section_options', 'gsf_create_preset_options' and more in various versions. This makes it possible for authenticated attackers, with Subscriber-level access and above, to reset and modify some of the plugin/theme settings. This issue was escalated to Envato over two months from the date of this disclosure and the issues, while partially patched, are still vulnerable. |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Tue, 06 May 2025 15:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
G5plus
G5plus april G5plus auteur G5plus benaa G5plus beyot |
|
| Weaknesses | CWE-862 | |
| CPEs | cpe:2.3:a:g5plus:april:*:*:*:*:*:wordpress:*:* cpe:2.3:a:g5plus:auteur:*:*:*:*:*:wordpress:*:* cpe:2.3:a:g5plus:benaa:*:*:*:*:*:wordpress:*:* cpe:2.3:a:g5plus:beyot:*:*:*:*:*:wordpress:*:* |
|
| Vendors & Products |
G5plus
G5plus april G5plus auteur G5plus benaa G5plus beyot |
Fri, 02 May 2025 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Fri, 02 May 2025 03:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Multiple plugins and/or themes for WordPress are vulnerable to unauthorized access due to a missing capability check on several AJAX actions like 'gsf_reset_section_options', 'gsf_reset_section_options', 'gsf_create_preset_options' and more in various versions. This makes it possible for authenticated attackers, with Subscriber-level access and above, to reset and modify some of the plugin/theme settings. This issue was escalated to Envato over two months from the date of this disclosure and the issues, while partially patched, are still vulnerable. | |
| Title | Smart Framework <= Multiple Plugins - Missing Authorization to Authenticated (Subscriber+) Settings Updates | |
| Weaknesses | CWE-94 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: Wordfence
Published:
Updated: 2025-05-02T14:52:43.113Z
Reserved: 2025-01-15T18:34:34.794Z
Link: CVE-2024-13420
Updated: 2025-05-02T14:52:21.173Z
Status : Analyzed
Published: 2025-05-02T04:15:46.047
Modified: 2025-05-06T15:26:47.970
Link: CVE-2024-13420
No data.
OpenCVE Enrichment
No data.
EUVD