CVE-2024-1771: Total <= 2.1.59 - Missing Authorization to Authenticated (Subscriber+) Sections Update
The Total theme for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the totalordersections() function in all versions up to, and including, 2.1.59. This makes it possible for authenticated attackers, with subscriber-level access and above, to repeat sections on the homepage.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2024-1771?
CVE-2024-1771 is considered a medium severity vulnerability due to its potential for unauthorized data modification.
How do I fix CVE-2024-1771?
To fix CVE-2024-1771, update the Total theme for WordPress to version 2.1.60 or later.
Who is affected by CVE-2024-1771?
Authenticated users with subscriber-level access and above can exploit CVE-2024-1771.
What function is vulnerable in CVE-2024-1771?
The vulnerability in CVE-2024-1771 stems from a missing capability check in the total_order_sections() function.
What versions are affected by CVE-2024-1771?
CVE-2024-1771 affects all versions of the Total theme for WordPress up to and including 2.1.59.