CVE-2024-7836: Themify Builder <= 7.6.1 - Missing Authorization to Authenticated (Contributor+) Post Duplication
The Themify Builder plugin for WordPress is vulnerable to unauthorized post duplication due to missing checks on the duplicatepageajaxify function in all versions up to, and including, 7.6.1. This makes it possible for authenticated attackers, with Contributor-level access and above, to duplicate and view private or draft posts created by other users that otherwise shouldn't be accessible to them.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-7836?
CVE-2024-7836 is assessed as a high-severity vulnerability due to the potential for unauthorized access and post duplication.
How do I fix CVE-2024-7836?
To fix CVE-2024-7836, update the Themify Builder plugin to version 7.6.2 or later.
Who is affected by CVE-2024-7836?
CVE-2024-7836 affects all versions of the Themify Builder plugin for WordPress up to and including version 7.6.1.
What type of attack can exploit CVE-2024-7836?
Authenticated attackers with Contributor-level access can exploit CVE-2024-7836 to duplicate posts without proper checks.
What functionality is compromised by CVE-2024-7836?
CVE-2024-7836 compromises the duplicate_page_ajaxify function, allowing unauthorized post duplication.