CVE-2024-1745

The Testimonial Slider WordPress plugin before 2.3.7 does not properly ensure that a user has the necessary capabilities to edit certain sensitive Testimonial Slider WordPress plugin before 2.3.7 settings, making it possible for users with at least the Author role to edit them.
Configurations

Configuration 1 (hide)

cpe:2.3:a:radiustheme:testimonial_slider_and_showcase:*:*:*:*:-:wordpress:*:*

History

07 May 2025, 01:27

Type Values Removed Values Added
References () https://wpscan.com/vulnerability/b63bbfeb-d6f7-4c33-8824-b86d64d3f598/ - () https://wpscan.com/vulnerability/b63bbfeb-d6f7-4c33-8824-b86d64d3f598/ - Exploit, Third Party Advisory
CWE NVD-CWE-noinfo
First Time Radiustheme
Radiustheme testimonial Slider And Showcase
CPE cpe:2.3:a:radiustheme:testimonial_slider_and_showcase:*:*:*:*:-:wordpress:*:*

21 Nov 2024, 08:51

Type Values Removed Values Added
References () https://wpscan.com/vulnerability/b63bbfeb-d6f7-4c33-8824-b86d64d3f598/ - () https://wpscan.com/vulnerability/b63bbfeb-d6f7-4c33-8824-b86d64d3f598/ -

05 Aug 2024, 19:35

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 4.3

26 Mar 2024, 12:55

Type Values Removed Values Added
Summary
  • (es) El complemento Testimonial Slider de WordPress anterior a 2.3.7 no garantiza adecuadamente que un usuario tenga las capacidades necesarias para editar ciertas configuraciones sensibles del complemento Testimonial Slider de WordPress anterior a 2.3.7, lo que hace posible que los usuarios con al menos el rol de Autor puedan editarlas.

26 Mar 2024, 05:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-03-26 05:15

Updated : 2025-05-07 01:27


NVD link : CVE-2024-1745

Mitre link : CVE-2024-1745

CVE.ORG link : CVE-2024-1745


JSON object : View

Products Affected

radiustheme

  • testimonial_slider_and_showcase