Record summary

CVE-2024-47308 has a selected CVSS score of 6.5 (medium); EIP currently links 1 Nuclei template.

Description

Missing Authorization vulnerability in WPDeveloper Templately templately.This issue affects Templately: from n/a through <= 3.1.2.

Description source: CVE List

Exploitation context

Known exploitation

VulnCheck KEV
Listed · Sep 27, 2024 · VulnCheck
Reported exploitation
Observed · VulnCheck

Available material

Nuclei templates
1

CISA SSVC decision

ExploitationNone
AutomatableYes
Technical impactPartial

CISA Coordinator · SSVC 2.0.3 · Evaluated Nov 1, 2024 · Source: CVE List

Affected products and versions

3
ProductSourceVersion rangeStatus

Elementor & Gutenberg Template Library: 5000+ Free & Pro Ready Templates & Cloud!

Browse Templately / Elementor & Gutenberg Template Library: 5000+ Free & Pro Ready Templates & Cloud!
VulnCheckVersion data not supplied

Default status: unaffected

CVE ListThrough 3.1.2affected

Default status: unknown

CVE ListThrough 3.1.2affected

Nuclei templates

1
ProjectDiscoveryMEDIUMTemplately <= 3.1.2 - Broken Access ControlCVSS 6.5

Templately allow an attacker to logout users who signed in to their templately account, so you can sign in your templately account to exploit this vulnerability. Go to http://IP/wordpress/wp-admin/admin.php?page=templately&path=sign-in to sign in then logout.

Impact

Attackers can access restricted functionalities, potentially leading to unauthorized actions or data exposure.

Remediation

Update to the latest version of Templately that addresses this issue.

WeaknessesCWE-862
Authorspopcorn94
Template tagscvecve2024wpscanwp-plugintemplatelywordpressvkev
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L
CPE: cpe:2.3:a:templately:templately:*:*:*:*:*:wordpress:*:*

Source: ProjectDiscovery

References

3