CVE-2024-6755: Social Auto Poster <= 5.3.14 - Missing Authorization to Unauthenticated Arbitrary Post Deletion
The Social Auto Poster plugin for WordPress is vulnerable to unauthorized modification and loss of data due to a missing capability check on the ‘wpwautoposterquickdeletemultiple’ function in all versions up to, and including, 5.3.14. This makes it possible for unauthenticated attackers to delete arbitrary posts.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-6755?
CVE-2024-6755 has been assessed as a high severity vulnerability due to the potential for unauthorized data modification.
How do I fix CVE-2024-6755?
To fix CVE-2024-6755, update the Social Auto Poster plugin to version 5.3.15 or later.
Who is affected by CVE-2024-6755?
CVE-2024-6755 affects all versions of the Social Auto Poster plugin for WordPress up to and including 5.3.14.
What type of vulnerability is CVE-2024-6755?
CVE-2024-6755 is a vulnerability related to unauthorized modification and data loss due to a missing capability check.
Can CVE-2024-6755 be exploited remotely?
Yes, CVE-2024-6755 can be exploited remotely by unauthenticated users due to its lack of proper access controls.