Description
The Sync Post With Other Site plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'sps_add_update_post' function in all versions up to, and including, 1.6. This makes it possible for authenticated attackers, with Subscriber-level access and above, to create new draft posts and update existing posts.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-47751 | The Sync Post With Other Site plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'sps_add_update_post' function in all versions up to, and including, 1.6. This makes it possible for authenticated attackers, with Subscriber-level access and above, to create new draft posts and update existing posts. |
References
History
Sat, 01 Mar 2025 02:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Syncpostwithothersite
Syncpostwithothersite sync Post With Other Site |
|
| CPEs | cpe:2.3:a:syncpostwithothersite:sync_post_with_other_site:*:*:*:*:*:wordpress:*:* | |
| Vendors & Products |
Syncpostwithothersite
Syncpostwithothersite sync Post With Other Site |
Status: PUBLISHED
Assigner: Wordfence
Published:
Updated: 2026-04-08T16:47:43.534Z
Reserved: 2024-07-11T22:49:40.823Z
Link: CVE-2024-6709
Updated: 2024-08-05T19:43:56.839Z
Status : Analyzed
Published: 2024-08-03T12:15:16.943
Modified: 2025-03-01T01:20:09.943
Link: CVE-2024-6709
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD