cve/2024/CVE-2024-7888.md
2025-09-29 21:09:30 +02:00

1.0 KiB
Raw Permalink Blame History

CVE-2024-7888

Description

The Classified Listing Classified ads & Business Directory Plugin plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on several functions like export_forms(), import_forms(), update_fb_options(), and many more in all versions up to, and including, 3.1.7. This makes it possible for authenticated attackers, with subscriber-level access and above, to modify forms and various other settings.

POC

Reference

No PoCs from references.

Github