CVE-2024-6012: Cost Calculator Builder <= 3.2.12 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Content Creation
The Cost Calculator Builder plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'embed-create-page' and 'embed-insert-pages' functions in all versions up to, and including, 3.2.12. This makes it possible for authenticated attackers, with Subscriber-level access and above, to create arbitrary posts and append arbitrary content to existing posts.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-6012?
CVE-2024-6012 is considered a high severity vulnerability due to its potential for unauthorized modification of data.
How do I fix CVE-2024-6012?
To fix CVE-2024-6012, update the Cost Calculator Builder plugin to version 3.2.13 or later.
Who is affected by CVE-2024-6012?
All users of the Cost Calculator Builder plugin for WordPress up to and including version 3.2.12 are affected by CVE-2024-6012.
What actions can be taken to mitigate CVE-2024-6012?
Mitigation steps for CVE-2024-6012 include applying the latest updates and implementing proper user access controls.
Is CVE-2024-6012 currently being exploited?
As of the latest information, there have been no confirmed incidents of CVE-2024-6012 being actively exploited in the wild.