CVE-2024-13419
Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
02/05/2025
Last modified:
06/05/2025
Description
Multiple plugins and/or themes for WordPress using Smart Framework are vulnerable to Stored Cross-Site Scripting due to a missing capability check on the saveOptions() and importThemeOptions() functions in various versions. This makes it possible for authenticated attackers, with Subscriber-level access and above, to update the plugin's settings which includes custom JavaScript that is enabled site-wide. This issue was escalated to Envato over two months from the date of this disclosure and the issue is still vulnerable.
Impact
Base Score 3.x
6.40
Severity 3.x
MEDIUM
Vulnerable products and versions
CPE | From | Up to |
---|---|---|
cpe:2.3:a:g5plus:april:*:*:*:*:*:wordpress:*:* | 5.1 (including) | |
cpe:2.3:a:g5plus:auteur:*:*:*:*:*:wordpress:*:* | 7.1 (including) | |
cpe:2.3:a:g5plus:benaa:*:*:*:*:*:wordpress:*:* | 4.0.0 (including) | |
cpe:2.3:a:g5plus:beyot:*:*:*:*:*:wordpress:*:* | 6.0.6 (including) |
To consult the complete list of CPE names with products and versions, see this page