CVE-2024-1047
EUVD-2024-1682302.02.2024, 06:15
Multiple plugins and/or themes for WordPress with the ThemeIsle SDK are vulnerable to unauthorized modification of data due to a missing capability check on the register_reference() function in various versions. This makes it possible for unauthenticated attackers to update options values that allow ThemeIsle to track promotional activities via utm_source.Enginsight
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| themeisle | orbit_fox | 𝑥 ≤ 2.10.28 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration
References