First published: Tue Jul 02 2024(Updated: )
The Cost Calculator Builder plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'embed-create-page' and 'embed-insert-pages' functions in all versions up to, and including, 3.2.12. This makes it possible for authenticated attackers, with Subscriber-level access and above, to create arbitrary posts and append arbitrary content to existing posts.
Credit: security@wordfence.com
Affected Software | Affected Version | How to fix |
---|---|---|
StylemixThemes Cost Calculator Builder | <3.2.13 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-6012 is considered a high severity vulnerability due to its potential for unauthorized modification of data.
To fix CVE-2024-6012, update the Cost Calculator Builder plugin to version 3.2.13 or later.
All users of the Cost Calculator Builder plugin for WordPress up to and including version 3.2.12 are affected by CVE-2024-6012.
Mitigation steps for CVE-2024-6012 include applying the latest updates and implementing proper user access controls.
As of the latest information, there have been no confirmed incidents of CVE-2024-6012 being actively exploited in the wild.