Zox News <= 3.17.0 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Options Modification
high
The Zox News - Professional WordPress News & Magazine Theme plugin for WordPress is vulnerable to unauthorized data modification. This vulnerability can lead to privilege escalation and denial of service conditions due to missing capability checks on the backup_options() and reset_options() functions in all versions up...
- CVSS:
- 8.8
- Affected:
- up to 3.17.0
- Fixed in:
- 3.17.1
- Disclosed:
- Feb 10, 2025
CVE-2024-13643 on NVD →
Zox News <= 3.16.0 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Options Update
high
The Zox News theme for WordPress is vulnerable to unauthorized modification of data that can lead to privilege escalation due to a missing capability check on the 'backup_options' and 'restore_options' function in all versions up to, and including, 3.16.0. This makes it possible for authenticated attackers, with Subscr...
- CVSS:
- 8.8
- Affected:
- up to 3.16.0
- Fixed in:
- 3.17.0
- Disclosed:
- Jan 25, 2025
CVE-2024-11936 on NVD →
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database