wordpress Vulnerabilities and Affected Products
Vulnerabilities associated with elespare.
Products
Clear product- WordPress28 vulnerabilities
- wordpress-develop17 vulnerabilities
- adserve2 vulnerabilities
- Core2 vulnerabilities
- geo_controller2 vulnerabilities
- max_addons_pro_for_bricks2 vulnerabilities
- royal-elementor-addons2 vulnerabilities
- absolutely_glamorous_custom_admin1 vulnerability
- acf-on-the-go1 vulnerability
- BuddyBoss Theme1 vulnerability
- Buddypress1 vulnerability
- buddypress_cover1 vulnerability
- checkout_mestres1 vulnerability
- contact_form_drag_and_drop_form_builder1 vulnerability
- counter_box1 vulnerability
- cssigniter_elements_team1 vulnerability
- customer_reviews_for_woocommerce1 vulnerability
- directorist1 vulnerability
- easy_social_feed1 vulnerability
- elementsready_addons_for_elementor1 vulnerability
- elespare1 vulnerability
- email_customizer_for_woocommerce1 vulnerability
- enl_newsletter1 vulnerability
- external_database_based_actions1 vulnerability
- File Manager Plugin1 vulnerability
| Vulnerability | Title and context | CVSS | EPSS | PoCs | Signals | STIX action |
|---|---|---|---|---|---|---|
CVE-2024-0900MEDIUM | Elespare – Build Your Blog, News & Magazine Websites with Expert-Designed Template Kits. One Click Import: No Coding Skills Required! <= 2.1.2 - Missing Authorization to Subscriber+ Arbitrary Post CreationThe Elespare – Build Your Blog, News & Magazine Websites with Expert-Designed Template Kits. One Click Import: No Coding Skills Required! plugin for WordPress is vulnerable to unauthorized post creation due to a missing capability check on the elespare_create_post() function hooked via AJAX in all versions up to, and including, 2.1.2. This makes it possible for authenticated attackers, with subscriber-level access and above, to create arbitrary posts. CWE-862Apr 23, 2024 | CVSS4.3v3.1 | EPSS0.371% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |