First published: Sat Jan 18 2025(Updated: )
The Evergreen Content Poster – Auto Post and Schedule Your Best Content to Social Media plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check on the delete_network_post() function in all versions up to, and including, 1.4.4. This makes it possible for unauthenticated attackers to delete arbitrary posts and pages.
Credit: security@wordfence.com
Affected Software | Affected Version | How to fix |
---|---|---|
<=1.4.4 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-12071 is classified as a medium severity vulnerability due to unauthorized loss of data.
To fix CVE-2024-12071, update the Evergreen Content Poster plugin to version 1.4.5 or higher.
CVE-2024-12071 affects all versions of Evergreen Content Poster up to and including 1.4.4.
CVE-2024-12071 impacts the delete_network_post() function, allowing unauthorized deletion of posts.
As of now, there are no public reports of active exploits specifically targeting CVE-2024-12071.