CVE-2024-0679: ColorMag <= 3.1.2 - Missing Authorization to Arbitrary Plugin Installation
The ColorMag theme for WordPress is vulnerable to unauthorized access due to a missing capability check on the pluginactioncallback() function in all versions up to, and including, 3.1.2. This makes it possible for authenticated attackers, with subscriber-level access and above, to install and activate arbitrary plugins.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2024-0679?
CVE-2024-0679 has a medium severity rating due to the risk of unauthorized actions by authenticated attackers.
How do I fix CVE-2024-0679?
To fix CVE-2024-0679, update the ColorMag theme to version 3.1.3 or later which includes the necessary capability checks.
Who is affected by CVE-2024-0679?
CVE-2024-0679 affects users of the ColorMag theme for WordPress, specifically those using versions up to 3.1.2.
What type of access does CVE-2024-0679 allow attackers?
CVE-2024-0679 allows authenticated attackers with subscriber-level access and above to perform unauthorized actions.
When was CVE-2024-0679 disclosed?
CVE-2024-0679 was disclosed recently, highlighting a vulnerability in the ColorMag theme affecting multiple versions.