CVE-2024-13419

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
02/05/2025
Last modified:
06/05/2025

Description

Multiple plugins and/or themes for WordPress using Smart Framework are vulnerable to Stored Cross-Site Scripting due to a missing capability check on the saveOptions() and importThemeOptions() functions in various versions. This makes it possible for authenticated attackers, with Subscriber-level access and above, to update the plugin's settings which includes custom JavaScript that is enabled site-wide. This issue was escalated to Envato over two months from the date of this disclosure and the issue is still vulnerable.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:g5plus:april:*:*:*:*:*:wordpress:*:* 5.1 (including)
cpe:2.3:a:g5plus:auteur:*:*:*:*:*:wordpress:*:* 7.1 (including)
cpe:2.3:a:g5plus:benaa:*:*:*:*:*:wordpress:*:* 4.0.0 (including)
cpe:2.3:a:g5plus:beyot:*:*:*:*:*:wordpress:*:* 6.0.6 (including)