CVE-2024-6750: Social Auto Poster <= 5.3.14 - Missing Authorization via Multiple Functions
The Social Auto Poster plugin for WordPress is vulnerable to unauthorized access, modification, and loss of data due to a missing capability check on multiple functions in all versions up to, and including, 5.3.14. This makes it possible for unauthenticated attackers to add, modify, or delete post meta and plugin options.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-6750?
CVE-2024-6750 is considered a high-severity vulnerability due to the potential for unauthorized access and data modification.
How do I fix CVE-2024-6750?
To fix CVE-2024-6750, update the Social Auto Poster plugin to version 5.3.15 or later.
Which versions are affected by CVE-2024-6750?
CVE-2024-6750 affects all versions of the Social Auto Poster plugin up to and including 5.3.14.
What types of attacks can occur due to CVE-2024-6750?
Due to CVE-2024-6750, unauthenticated attackers can add, modify, or delete content within the plugin.
Who is impacted by CVE-2024-6750?
WordPress sites using the Social Auto Poster plugin version 5.3.14 or earlier are impacted by CVE-2024-6750.