CVE · Medium

CVE-2024-34820 — If-So Dynamic Content – Elementor & All Page Builders Personalization [if-so] < 1.7.1.1

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2024-34820 If-So Dynamic Content – Elementor & All Page Builders Personalization [if-so] < 1.7.1.1 Missing Authorization Medium 6.5 < 1.7.1.1 1.7.1.1 2024-05-09

CVE-2024-34820

The If-So Dynamic Content Personalization plugin for WordPress contains a vulnerability in versions 1.7.1 and earlier where the edd_ifso_clear_license() function lacks proper capability verification. This flaw allows unauthenticated users to remove licenses from the plugin. The vulnerability stems from insufficient access controls on a critical administrative function.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.