CVE-2024-7888: Classified Listing – Classified ads & Business Directory Plugin <= 3.1.7 - Missing Authorization
The Classified Listing – Classified ads & Business Directory Plugin plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on several functions like exportforms(), importforms(), updatefboptions(), and many more in all versions up to, and including, 3.1.7. This makes it possible for authenticated attackers, with subscriber-level access and above, to modify forms and various other settings.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2024-7888?
CVE-2024-7888 is classified as a high-severity vulnerability due to its potential for unauthorized access.
How do I fix CVE-2024-7888?
To fix CVE-2024-7888, ensure that you update the Classified Listing – Classified ads & Business Directory Plugin to version 3.1.9 or higher.
What versions of the Classified Listing plugin are affected by CVE-2024-7888?
CVE-2024-7888 affects all versions of the Classified Listing plugin up to and including version 3.1.8.
What functions are vulnerable in CVE-2024-7888?
CVE-2024-7888 involves several functions including export_forms(), import_forms(), and update_fb_options() that lack proper capability checks.
Can CVE-2024-7888 lead to data exposure?
Yes, CVE-2024-7888 can potentially allow unauthorized users to access sensitive data through the vulnerable functions.