The Trash Duplicate and 301 Redirect plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check on the 'duplicates-action-top' action in all versions up to, and including, 1.9. This makes it possible for unauthenticated attackers to delete arbitrary posts/pages.
Metrics
Affected Vendors & Products
References
History
Wed, 19 Feb 2025 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 19 Feb 2025 07:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The Trash Duplicate and 301 Redirect plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check on the 'duplicates-action-top' action in all versions up to, and including, 1.9. This makes it possible for unauthenticated attackers to delete arbitrary posts/pages. | |
| Title | Trash Duplicate and 301 Redirect <= 1.9 - Missing Authorization to Unauthenticated Arbitrary Post Deletion | |
| Weaknesses | CWE-862 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: Wordfence
Published: 2025-02-19T07:32:14.346Z
Updated: 2025-02-19T14:34:14.405Z
Reserved: 2025-01-16T15:47:36.339Z
Link: CVE-2024-13468
Updated: 2025-02-19T14:33:50.366Z
Status : Received
Published: 2025-02-19T08:15:16.027
Modified: 2025-02-19T08:15:16.027
Link: CVE-2024-13468
No data.