CVE-2024-6754: Social Auto Poster <= 5.3.14 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Post Meta Update via wpw_auto_poster_update_tweet_template
The Social Auto Poster plugin for WordPress is vulnerable to unauthorized modification of data to a missing capability check on the ‘wpwautoposterupdatetweettemplate’ function in all versions up to, and including, 5.3.14. This makes it possible for authenticated attackers, with Subscriber-level access and above, to update arbitrary post metadata.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-6754?
CVE-2024-6754 has a high severity due to the potential for unauthorized data modification.
How do I fix CVE-2024-6754?
To fix CVE-2024-6754, update the Social Auto Poster plugin to version 5.3.15 or higher.
Who is affected by CVE-2024-6754?
CVE-2024-6754 affects all versions of the Social Auto Poster plugin for WordPress up to and including 5.3.14.
What type of attack is possible with CVE-2024-6754?
CVE-2024-6754 allows authenticated attackers to modify data without proper authorization.
Is it safe to use earlier versions of the Social Auto Poster plugin with CVE-2024-6754?
It is not safe to use earlier versions of the Social Auto Poster plugin due to the vulnerability found in CVE-2024-6754.