CVE-2024-6709CVSS 4.3Web
CVE-2024-6709: sync post with other site vulnerability
The Sync Post With Other Site plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'sps_add_update_post' function in all versions up to, and including, 1.6. This makes it possible for authenticated attackers, with Subscriber-level access and above, to create new draft posts and update existing posts.
- CVSS
- 4.3 MEDIUM
- EPSS
- 24.69%
- Known exploited
- not in KEV
- Product
- sync post with other site
What is known
The Sync Post With Other Site plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'sps_add_update_post' function in all versions up to, and including, 1.6. This makes it possible for authenticated attackers, with Subscriber-level access and above, to create new draft posts and update existing posts.