Multiple plugins and/or themes for WordPress using Smart Framework are vulnerable to Stored Cross-Site Scripting due to a missing capability check on the saveOptions() and importThemeOptions() functions in various versions. This makes it possible for authenticated attackers, with Subscriber-level access and above, to update the plugin's settings which includes custom JavaScript that is enabled site-wide. This issue was escalated to Envato over two months from the date of this disclosure and the issue is still vulnerable.
References
Link | Resource |
---|---|
https://themeforest.net/item/beyot-wordpress-real-estate-theme/19514964 | Product |
https://www.wordfence.com/threat-intel/vulnerabilities/id/07729c28-a73a-46f4-853e-116792d612f5?source=cve | Third Party Advisory |
Configurations
Configuration 1 (hide)
|
History
06 May 2025, 14:57
Type | Values Removed | Values Added |
---|---|---|
Summary |
|
|
References | () https://themeforest.net/item/beyot-wordpress-real-estate-theme/19514964 - Product | |
References | () https://www.wordfence.com/threat-intel/vulnerabilities/id/07729c28-a73a-46f4-853e-116792d612f5?source=cve - Third Party Advisory | |
First Time |
G5plus april
G5plus benaa G5plus beyot G5plus auteur G5plus |
|
CPE | cpe:2.3:a:g5plus:auteur:*:*:*:*:*:wordpress:*:* cpe:2.3:a:g5plus:april:*:*:*:*:*:wordpress:*:* cpe:2.3:a:g5plus:benaa:*:*:*:*:*:wordpress:*:* cpe:2.3:a:g5plus:beyot:*:*:*:*:*:wordpress:*:* |
02 May 2025, 04:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2025-05-02 04:15
Updated : 2025-05-06 14:57
NVD link : CVE-2024-13419
Mitre link : CVE-2024-13419
CVE.ORG link : CVE-2024-13419
JSON object : View
Products Affected
g5plus
- beyot
- benaa
- auteur
- april
CWE
CWE-862
Missing Authorization