cleantalk
Vulnerabilities and Security Researches

The Ultimate WordPress Toolkit – WP Extended, CVE-2024-13554

CVE, Research URL

CVE-2024-13554

Published on
Feb 12, 2025
Research Description
The The Ultimate WordPress Toolkit – WP Extended plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the reorder_route() function in all versions up to, and including, 3.0.13. This makes it possible for unauthenticated attackers to reorder posts.
Affected versions
Min -, max 3.0.14.
Status
vulnerable