The Cost Calculator Builder plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'embed-create-page' and 'embed-insert-pages' functions in all versions up to, and including, 3.2.12. This makes it possible for authenticated attackers, with Subscriber-level access and above, to create arbitrary posts and append arbitrary content to existing posts.
Metrics
Affected Vendors & Products
References
History
No history.
MITRE
Status: PUBLISHED
Assigner: Wordfence
Published: 2024-07-02T09:32:10.221Z
Updated: 2024-08-01T21:25:03.191Z
Reserved: 2024-06-14T17:02:30.798Z
Link: CVE-2024-6012
Vulnrichment
Updated: 2024-08-01T21:25:03.191Z
NVD
Status : Modified
Published: 2024-07-02T10:15:09.367
Modified: 2024-11-21T09:48:44.820
Link: CVE-2024-6012
Redhat
No data.