CVE-2024-11583

The Borderless – Widgets, Elements, Templates and Toolkit for Elementor & Gutenberg plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check on the 'remove_zipped_font' function in all versions up to, and including, 1.5.9. This makes it possible for authenticated attackers, with Subscriber-level access and above, to delete icon fonts that were previously uploaded.
Configurations

Configuration 1 (hide)

cpe:2.3:a:visualmodo:borderless:*:*:*:*:*:wordpress:*:*

History

31 Jan 2025, 20:03

Type Values Removed Values Added
CPE cpe:2.3:a:visualmodo:borderless:*:*:*:*:*:wordpress:*:*
First Time Visualmodo borderless
Visualmodo
References () https://plugins.trac.wordpress.org/browser/borderless/tags/1.5.7/includes/icon-manager/icon-manager.php#L270 - () https://plugins.trac.wordpress.org/browser/borderless/tags/1.5.7/includes/icon-manager/icon-manager.php#L270 - Product
References () https://www.wordfence.com/threat-intel/vulnerabilities/id/0968fe3b-2256-41e8-8cc9-e800dd7f8c27?source=cve - () https://www.wordfence.com/threat-intel/vulnerabilities/id/0968fe3b-2256-41e8-8cc9-e800dd7f8c27?source=cve - Third Party Advisory
Summary
  • (es) El complemento Borderless – Widgets, Elements, Templates and Toolkit for Elementor & Gutenberg para WordPress es vulnerable a la pérdida no autorizada de datos debido a una verificación de capacidad faltante en la función 'remove_zipped_font' en todas las versiones hasta la 1.5.9 y incluida. Esto permite que atacantes autenticados, con acceso de nivel de suscriptor y superior, eliminen fuentes de íconos que se cargaron previamente.

30 Jan 2025, 14:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-01-30 14:15

Updated : 2025-01-31 20:03


NVD link : CVE-2024-11583

Mitre link : CVE-2024-11583

CVE.ORG link : CVE-2024-11583


JSON object : View

Products Affected

visualmodo

  • borderless
CWE
CWE-862

Missing Authorization