CVE-2024-0791

MEDIUM

Pluginus Wolf - Wordpress Posts Bulk Editor And Products Manager Professional < 1.0.8.1 - Missing Authorization

Title source: rule
STIX 2.1

Description

The WOLF – WordPress Posts Bulk Editor and Manager Professional plugin for WordPress is vulnerable to unauthorized access, modification or loss of data due to a missing capability check on the wpbe_create_new_term, wpbe_update_tax_term, and wpbe_delete_tax_term functions in all versions up to, and including, 1.0.8.1. This makes it possible for authenticated attackers, with subscriber access or higher, to create, delete or modify taxonomy terms.

Scores

CVSS v3 4.3
EPSS 0.0053
EPSS Percentile 41.1%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-862
Status published
Products (2)
pluginus/wolf_-_wordpress_posts_bulk_editor_and_products_manager_professional < 1.0.8.1
realmag777/WOLF – WordPress Posts Bulk Editor and Manager Professional < 1.0.8.1
Published Feb 05, 2024
Tracked Since Feb 18, 2026