CVE-2024-47308
WordPress Templately plugin <= 3.1.2 - Broken Access Control vulnerability
Record summary
CVE-2024-47308 has a selected CVSS score of 6.5 (medium); EIP currently links 1 Nuclei template.
Description
Missing Authorization vulnerability in WPDeveloper Templately templately.This issue affects Templately: from n/a through <= 3.1.2.
Exploitation context
Known exploitation
- VulnCheck KEV
- Listed · Sep 27, 2024 · VulnCheck
- Reported exploitation
- Observed · VulnCheck
Available material
- Nuclei templates
- 1
CISA SSVC decision
CISA Coordinator · SSVC 2.0.3 · Evaluated Nov 1, 2024 · Source: CVE List
Affected products and versions
3| Product | Source | Version range | Status |
|---|---|---|---|
Elementor & Gutenberg Template Library: 5000+ Free & Pro Ready Templates & Cloud!Browse Templately / Elementor & Gutenberg Template Library: 5000+ Free & Pro Ready Templates & Cloud! | VulnCheck | Version data not supplied | |
TemplatelyBrowse WPDeveloper / TemplatelyDefault status: unaffected | CVE List | Through 3.1.2 | affected |
templatelyBrowse templately / templatelyDefault status: unknown | CVE List | Through 3.1.2 | affected |
Nuclei templates
1ProjectDiscoveryMEDIUMTemplately <= 3.1.2 - Broken Access ControlCVSS 6.5
Templately allow an attacker to logout users who signed in to their templately account, so you can sign in your templately account to exploit this vulnerability. Go to http://IP/wordpress/wp-admin/admin.php?page=templately&path=sign-in to sign in then logout.
Impact
Attackers can access restricted functionalities, potentially leading to unauthorized actions or data exposure.
Remediation
Update to the latest version of Templately that addresses this issue.
Source: ProjectDiscovery