SchedulePress <= 5.1.3 - Unauthenticated Full Path Disclosure
medium
The SchedulePress – Auto Post & Publish, Auto Social Share, Schedule Posts with Editorial Calendar & Missed Schedule Post Publisher plugin for WordPress is vulnerable to Full Path Disclosure in all versions up to, and including, 5.1.3. This is due the plugin utilizing the wpdeveloper library and leaving the demo files...
- CVSS:
- 5.3
- Affected:
- up to 5.1.3
- Fixed in:
- 5.1.4
- Disclosed:
- Jul 15, 2024
CVE-2024-6557 on NVD →
SchedulePress <= 5.0.8 - Missing Authorization
medium
The SchedulePress plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in versions up to, and including, 5.0.8. This makes it possible for authenticated attackers, with subscriber-level access and above, to perform an unauthorized action.
- CVSS:
- 4.3
- Affected:
- up to 5.0.8
- Fixed in:
- 5.0.9
- Disclosed:
- Apr 22, 2024
CVE-2024-32717 on NVD →
SchedulePress <= 5.0.4 - Insufficient Authorization to Authenticated (Contributor+) Arbitrary Post Modifications
medium
The SchedulePress – Best Editorial Calendar, Missed Schedule & Auto Social Share plugin for WordPress is vulnerable to unauthorized modification of data due to improper capability checks on several REST API endpoints in all versions up to, and including, 5.0.4. This makes it possible for authenticated attackers, with c...
- CVSS:
- 4.3
- Affected:
- up to 5.0.4
- Fixed in:
- 5.0.5
- Disclosed:
- Nov 28, 2023
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database