Multiple plugins and/or themes for WordPress are vulnerable to unauthorized access due to a missing capability check on several AJAX actions like 'gsf_reset_section_options', 'gsf_reset_section_options', 'gsf_create_preset_options' and more in various versions. This makes it possible for authenticated attackers, with Subscriber-level access and above, to reset and modify some of the plugin/theme settings. This issue was escalated to Envato over two months from the date of this disclosure and the issues, while partially patched, are still vulnerable.
References
Link | Resource |
---|---|
https://themeforest.net/item/beyot-wordpress-real-estate-theme/19514964 | Product |
https://www.wordfence.com/threat-intel/vulnerabilities/id/6d484422-4adf-4370-b228-61496d5ad78a?source=cve | Third Party Advisory |
Configurations
Configuration 1 (hide)
|
History
06 May 2025, 15:26
Type | Values Removed | Values Added |
---|---|---|
Summary |
|
|
First Time |
G5plus april
G5plus benaa G5plus beyot G5plus auteur G5plus |
|
CPE | cpe:2.3:a:g5plus:auteur:*:*:*:*:*:wordpress:*:* cpe:2.3:a:g5plus:april:*:*:*:*:*:wordpress:*:* cpe:2.3:a:g5plus:benaa:*:*:*:*:*:wordpress:*:* cpe:2.3:a:g5plus:beyot:*:*:*:*:*:wordpress:*:* |
|
CWE | CWE-862 | |
References | () https://themeforest.net/item/beyot-wordpress-real-estate-theme/19514964 - Product | |
References | () https://www.wordfence.com/threat-intel/vulnerabilities/id/6d484422-4adf-4370-b228-61496d5ad78a?source=cve - Third Party Advisory |
02 May 2025, 04:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2025-05-02 04:15
Updated : 2025-05-06 15:26
NVD link : CVE-2024-13420
Mitre link : CVE-2024-13420
CVE.ORG link : CVE-2024-13420
JSON object : View
Products Affected
g5plus
- beyot
- benaa
- auteur
- april