CVE-2024-10078CVSS 6.3Web
CVE-2024-10078: wp easy post types vulnerability
The WP Easy Post Types plugin for WordPress is vulnerable to unauthorized access, modification, and loss of data due to a missing capability check on multiple functions in all versions up to, and including, 1.4.4. This makes it possible for authenticated attackers, with subscriber-level access and above, to add, modify, or delete plugin options and posts.
- CVSS
- 6.3 MEDIUM
- EPSS
- 33.6%
- Known exploited
- not in KEV
- Product
- wp easy post types
What is known
The WP Easy Post Types plugin for WordPress is vulnerable to unauthorized access, modification, and loss of data due to a missing capability check on multiple functions in all versions up to, and including, 1.4.4. This makes it possible for authenticated attackers, with subscriber-level access and above, to add, modify, or delete plugin options and posts.