CVE-2024-0839

T

he FeedWordPress plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 2022.0222 due to missing validation on the user controlled 'guid' key. This makes it possible for unauthenticated attackers to view draft posts that may contain sensitive information.

Configurations

Configuration 1 (hide)

cpe:2.3:a:feedwordpress_project:feedwordpress:*:*:*:*:*:wordpress:*:*

History

11 Mar 2025, 13:25

Type Values Removed Values Added
CPE cpe:2.3:a:feedwordpress_project:feedwordpress:*:*:*:*:*:wordpress:*:*
CWE CWE-639
First Time Feedwordpress Project feedwordpress
Feedwordpress Project
References () https://wordpress.org/plugins/feedwordpress/ - () https://wordpress.org/plugins/feedwordpress/ - Product
References () https://www.wordfence.com/threat-intel/vulnerabilities/id/1ead46fd-5744-4fbb-9efd-980f9216abbc?source=cve - () https://www.wordfence.com/threat-intel/vulnerabilities/id/1ead46fd-5744-4fbb-9efd-980f9216abbc?source=cve - Third Party Advisory

21 Nov 2024, 08:47

Type Values Removed Values Added
References () https://wordpress.org/plugins/feedwordpress/ - () https://wordpress.org/plugins/feedwordpress/ -
References () https://www.wordfence.com/threat-intel/vulnerabilities/id/1ead46fd-5744-4fbb-9efd-980f9216abbc?source=cve - () https://www.wordfence.com/threat-intel/vulnerabilities/id/1ead46fd-5744-4fbb-9efd-980f9216abbc?source=cve -

Information

Published : 2024-03-13 16:15

Updated : 2025-03-11 13:25


NVD link : CVE-2024-0839

Mitre link : CVE-2024-0839

CVE.ORG link : CVE-2024-0839


JSON object : View

CWE
CWE-639

Authorization Bypass Through User-Controlled Key