Description
The Spice Starter Sites plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the spice_starter_sites_importer_creater function in all versions up to, and including, 1.2.5. This makes it possible for unauthenticated attackers to import demo content.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-49169 | The Spice Starter Sites plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the spice_starter_sites_importer_creater function in all versions up to, and including, 1.2.5. This makes it possible for unauthenticated attackers to import demo content. |
References
History
Tue, 01 Oct 2024 14:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Spicethemes
Spicethemes spice Starter Sites |
|
| CPEs | cpe:2.3:a:spicethemes:spice_starter_sites:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Spicethemes
Spicethemes spice Starter Sites |
|
| Metrics |
ssvc
|
Tue, 01 Oct 2024 08:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The Spice Starter Sites plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the spice_starter_sites_importer_creater function in all versions up to, and including, 1.2.5. This makes it possible for unauthenticated attackers to import demo content. | |
| Title | Spice Starter Sites <= 1.2.5 - Missing Authorization to Unauthenticated Demo Content Import | |
| Weaknesses | CWE-862 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: Wordfence
Published:
Updated: 2026-04-08T17:31:24.143Z
Reserved: 2024-09-04T15:27:14.463Z
Link: CVE-2024-8430
Updated: 2024-10-01T13:29:23.187Z
Status : Awaiting Analysis
Published: 2024-10-01T09:15:03.790
Modified: 2024-10-04T13:51:25.567
Link: CVE-2024-8430
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD