The Page and Post Clone plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 6.0 via the 'content_clone' function due to missing validation on a user controlled key. This makes it possible for authenticated attackers, with Author-level access and above, to clone and read private posts.
Advisories
Source ID Title
EUVD EUVD EUVD-2024-47071 The Page and Post Clone plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 6.0 via the 'content_clone' function due to missing validation on a user controlled key. This makes it possible for authenticated attackers, with Author-level access and above, to clone and read private posts.
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

No history.

Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: Wordfence

Published:

Updated: 2024-08-01T21:25:03.191Z

Reserved: 2024-06-12T23:04:28.288Z

Link: CVE-2024-5942

cve-icon Vulnrichment

Updated: 2024-08-01T21:25:03.191Z

cve-icon NVD

Status : Modified

Published: 2024-06-29T05:15:03.360

Modified: 2024-11-21T09:48:37.157

Link: CVE-2024-5942

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses