CVE-2024-13318

The Essential WP Real Estate plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on the cl_delete_listing_func() function in all versions up to, and including, 1.1.3. This makes it possible for unauthenticated attackers to delete arbitrary pages and posts.
Configurations

Configuration 1 (hide)

cpe:2.3:a:smartdatasoft:essential_wp_real_estate:*:*:*:*:*:wordpress:*:*

History

25 Feb 2025, 16:49

Type Values Removed Values Added
First Time Smartdatasoft essential Wp Real Estate
Smartdatasoft
Summary
  • (es) El complemento Essential WP Real Estate para WordPress es vulnerable al acceso no autorizado debido a una verificación de capacidad faltante en la función cl_delete_listing_func() en todas las versiones hasta la 1.1.3 incluida. Esto permite que atacantes no autenticados eliminen páginas y publicaciones arbitrarias.
CWE NVD-CWE-Other
CPE cpe:2.3:a:smartdatasoft:essential_wp_real_estate:*:*:*:*:*:wordpress:*:*
References () https://plugins.trac.wordpress.org/browser/essential-wp-real-estate/trunk/src/Common/Ajax/Ajax.php#L724 - () https://plugins.trac.wordpress.org/browser/essential-wp-real-estate/trunk/src/Common/Ajax/Ajax.php#L724 - Product
References () https://www.wordfence.com/threat-intel/vulnerabilities/id/6a1a9e22-d174-43fc-aab6-f6968067a290?source=cve - () https://www.wordfence.com/threat-intel/vulnerabilities/id/6a1a9e22-d174-43fc-aab6-f6968067a290?source=cve - Third Party Advisory

10 Jan 2025, 12:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-01-10 12:15

Updated : 2025-02-25 16:49


NVD link : CVE-2024-13318

Mitre link : CVE-2024-13318

CVE.ORG link : CVE-2024-13318


JSON object : View

Products Affected

smartdatasoft

  • essential_wp_real_estate
CWE
CWE-463

Deletion of Data Structure Sentinel

NVD-CWE-Other