CVE-2024-13703: CRM and Lead Management by vcita <= 2.7.5 - Missing Authorization to Authenticated (Susbcriber+) Widget Toggle
The CRM and Lead Management by vcita plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the vcitaajaxtoggleae() function in all versions up to, and including, 2.7.5. This makes it possible for authenticated attackers, with Subscriber-level access and above, to enable and disable plugin widgets.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-13703?
CVE-2024-13703 is considered a high-severity vulnerability due to its potential for unauthorized data modification.
How do I fix CVE-2024-13703?
To fix CVE-2024-13703, update the VCita CRM and Lead Management plugin to version 2.7.2 or later.
Who is affected by CVE-2024-13703?
Any users of the VCita CRM and Lead Management plugin for WordPress, specifically versions up to and including 2.7.1, are affected by CVE-2024-13703.
What is the impact of CVE-2024-13703?
The impact of CVE-2024-13703 includes the potential for authenticated attackers to modify data without proper authorization.
Is CVE-2024-13703 related to WordPress security?
Yes, CVE-2024-13703 directly affects the security of WordPress sites using the VCita CRM and Lead Management plugin.