CVE-2024-4199: Bulk Posts Editing For WordPress <= 4.2.3 - Authenticated (Subscriber+) Missing Authorization
The Bulk Posts Editing For WordPress plugin for WordPress is vulnerable to unauthorized access of functionality due to a missing capability check on the plugin's AJAX actions in all versions up to, and including, 4.2.3. This makes it possible for authenticated attackers, with subscriber access and higher, to invoke their corresponding functions. This may lead to post creation and duplication, post content retrieval, post taxonomy manipulation.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-4199?
The severity of CVE-2024-4199 is considered high due to the potential for unauthorized access and exploitation by authenticated attackers.
How do I fix CVE-2024-4199?
To fix CVE-2024-4199, update the Bulk Posts Editing plugin to version 4.2.4 or later where the vulnerability is addressed.
Who is affected by CVE-2024-4199?
CVE-2024-4199 affects all versions of the Bulk Posts Editing for WordPress plugin up to and including version 4.2.3.
What are the consequences of CVE-2024-4199?
The consequences of CVE-2024-4199 include the risk of unauthorized functionality access that can lead to data manipulation or compromise.
How can I determine if I am vulnerable to CVE-2024-4199?
You can determine if you are vulnerable to CVE-2024-4199 by checking if your Bulk Posts Editing plugin version is 4.2.3 or earlier.