CVE-2024-7429: Zotpress <= 7.3.12 - Missing Authorization
The Zotpress plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the ZotpressprocessaccountsAJAX function in all versions up to, and including, 7.3.12. This makes it possible for authenticated attackers, with Contributor-level access and above, to reset the plugin's settings.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2024-7429?
CVE-2024-7429 is classified as a high severity vulnerability due to the potential for unauthorized modification of data.
How do I fix CVE-2024-7429?
To fix CVE-2024-7429, update the Zotpress plugin to version 7.3.13 or later.
Who is affected by CVE-2024-7429?
CVE-2024-7429 affects users of the Zotpress plugin for WordPress up to and including version 7.3.12.
What is the nature of the vulnerability in CVE-2024-7429?
CVE-2024-7429 is a vulnerability that allows authenticated attackers to perform unauthorized data modifications due to a missing capability check.
Is there a patch for CVE-2024-7429?
Yes, the patch for CVE-2024-7429 is included in Zotpress version 7.3.13.