CVE-2024-12071: Evergreen Content Poster – Auto Post and Schedule Your Best Content to Social Media <= 1.4.4 - Missing Authorization to Unauthenticated Arbitrary Post Deletion
The Evergreen Content Poster – Auto Post and Schedule Your Best Content to Social Media plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check on the deletenetworkpost() function in all versions up to, and including, 1.4.4. This makes it possible for unauthenticated attackers to delete arbitrary posts and pages.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2024-12071?
CVE-2024-12071 is classified as a medium severity vulnerability due to unauthorized loss of data.
How do I fix CVE-2024-12071?
To fix CVE-2024-12071, update the Evergreen Content Poster plugin to version 1.4.5 or higher.
What versions are affected by CVE-2024-12071?
CVE-2024-12071 affects all versions of Evergreen Content Poster up to and including 1.4.4.
What functionality is impacted by CVE-2024-12071?
CVE-2024-12071 impacts the delete_network_post() function, allowing unauthorized deletion of posts.
Is there a known exploit for CVE-2024-12071?
As of now, there are no public reports of active exploits specifically targeting CVE-2024-12071.