CVE-2024-3893: Classified Listing – Classified ads & Business Directory Plugin <= 3.0.10.3 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Attachment Deletion
The Classified Listing – Classified ads & Business Directory Plugin plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check on the rtclfbgalleryimagedelete AJAX action in all versions up to, and including, 3.0.10.3. This makes it possible for authenticated attackers, with subscriber-level access and above, to delete arbitrary attachements.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2024-3893?
CVE-2024-3893 is classified with a high severity due to unauthorized data loss potential.
How do I fix CVE-2024-3893?
To fix CVE-2024-3893, update the Classified Listing – Classified ads & Business Directory Plugin to version 3.0.10.4 or higher.
Who is affected by CVE-2024-3893?
Any WordPress site using the Classified Listing – Classified ads & Business Directory Plugin version 3.0.10.3 or earlier is affected by CVE-2024-3893.
What does CVE-2024-3893 exploit?
CVE-2024-3893 exploits a missing capability check on the rtcl_fb_gallery_image_delete AJAX action, allowing unauthorized access to data deletion.
Is there a workaround for CVE-2024-3893?
A temporary workaround for CVE-2024-3893 is to manually restrict access to the plugin until an update is applied.