CVE-2024-13318

The Essential WP Real Estate plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on the cl_delete_listing_func() function in all versions up to, and including, 1.1.3. This makes it possible for unauthenticated attackers to delete arbitrary pages and posts.
Configurations

Configuration 1 (hide)

cpe:2.3:a:smartdatasoft:essential_wp_real_estate:*:*:*:*:*:wordpress:*:*

History

No history.

Information

Published : 2025-01-10 12:15

Updated : 2025-02-25 16:49


NVD link : CVE-2024-13318

Mitre link : CVE-2024-13318

CVE.ORG link : CVE-2024-13318


JSON object : View

Products Affected

smartdatasoft

  • essential_wp_real_estate
CWE
CWE-463

Deletion of Data Structure Sentinel

NVD-CWE-Other