CVE-2024-2538: Permalink Manager <= 2.4.3.1 - Missing Authorization to Authenticated(Author+) Arbitrary Post Slug Modification
The Permalink Manager Lite plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'ajaxsavepermalink' function in all versions up to, and including, 2.4.3.1. This makes it possible for authenticated attackers, with author access and above, to modify the permalinks of arbitrary posts.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2024-2538?
CVE-2024-2538 is classified as a medium severity vulnerability due to the potential for unauthorized data modification by authenticated attackers.
How do I fix CVE-2024-2538?
To fix CVE-2024-2538, update the Permalink Manager Lite plugin to version 2.4.3.2 or later.
Who is affected by CVE-2024-2538?
CVE-2024-2538 affects all users of the Permalink Manager Lite plugin for WordPress versions up to and including 2.4.3.1.
What kind of attacks can exploit CVE-2024-2538?
CVE-2024-2538 can be exploited by authenticated attackers with author access or higher, allowing them to modify permalinks.
What is the function impacted by CVE-2024-2538?
The 'ajax_save_permalink' function is impacted by CVE-2024-2538 due to a missing capability check.