CVE-2024-1047: ThemeIsle SDK <= Various Versions - Missing Authorization
Multiple plugins and/or themes for WordPress with the ThemeIsle SDK are vulnerable to unauthorized modification of data due to a missing capability check on the registerreference() function in various versions. This makes it possible for unauthenticated attackers to update options values that allow ThemeIsle to track promotional activities via utmsource.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-1047?
CVE-2024-1047 is rated as a medium severity vulnerability due to the potential for unauthorized data modification.
How do I fix CVE-2024-1047?
To remediate CVE-2024-1047, update the Orbit Fox by ThemeIsle plugin to version 2.10.29 or later.
Who is affected by CVE-2024-1047?
All users of the Orbit Fox by ThemeIsle plugin for WordPress, up to and including version 2.10.28, are affected by CVE-2024-1047.
What kind of attacks are possible due to CVE-2024-1047?
CVE-2024-1047 allows unauthenticated attackers to modify connected API keys, which could lead to further exploitation.
Is authentication required to exploit CVE-2024-1047?
No, CVE-2024-1047 can be exploited by unauthenticated attackers due to a missing capability check.