SB2025013136 - Missing Authorization in Evergreen Content Poster – Auto Post and Schedule Your Best Content to Social Media plugin for WordPress
Published: January 31, 2025
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Missing Authorization (CVE-ID: CVE-2024-12071)
The vulnerability allows a remote attacker to bypass authorization checks.
The vulnerability exists due to a missing capability check on the delete_network_post() function. A remote attacker can delete arbitrary posts and pages.
Remediation
Install update from vendor's website.
References
- https://plugins.trac.wordpress.org/browser/evergreen-content-poster/trunk/admin/class-evergreen_content_poster-admin.php#L333
- https://plugins.trac.wordpress.org/browser/evergreen-content-poster/trunk/includes/class-evergreen_content_poster.php#L345
- https://plugins.trac.wordpress.org/changeset?sfp_email=&sfph_mail=&reponame=&old=3224190%40evergreen-content-poster&new=3224190%40evergreen-content-poster&sfp_email=&sfph_mail=
- https://www.wordfence.com/threat-intel/vulnerabilities/id/aa07f48f-370f-4985-a6fc-a94ed5c59ed4?source=cve