The zStore Manager Basic plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check on the zstore_clear_cache() function in all versions up to, and including, 3.311. This makes it possible for authenticated attackers, with Subscriber-level access and above, to clear the plugin's cache.
History

Thu, 30 Jan 2025 19:15:00 +0000

Type Values Removed Values Added
First Time appeared Ikjweb
Ikjweb zstore Manager Basic
CPEs cpe:2.3:a:ikjweb:zstore_manager_basic:*:*:*:*:*:wordpress:*:*
Vendors & Products Ikjweb
Ikjweb zstore Manager Basic

Thu, 30 Jan 2025 15:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 30 Jan 2025 14:00:00 +0000

Type Values Removed Values Added
Description The zStore Manager Basic plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check on the zstore_clear_cache() function in all versions up to, and including, 3.311. This makes it possible for authenticated attackers, with Subscriber-level access and above, to clear the plugin's cache.
Title zStore Manager Basic <= 3.311 - Missing Authorization to Authenticated (Subscriber+) Cache Clearing
Weaknesses CWE-862
References
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: Wordfence

Published:

Updated: 2025-01-30T14:38:59.908Z

Reserved: 2025-01-24T15:18:08.054Z

Link: CVE-2024-13715

cve-icon Vulnrichment

Updated: 2025-01-30T14:36:47.109Z

cve-icon NVD

Status : Analyzed

Published: 2025-01-30T14:15:36.513

Modified: 2025-01-30T18:53:45.883

Link: CVE-2024-13715

cve-icon Redhat

No data.