CVE · Medium

CVE-2024-4280 — White Label CMS [white-label-cms] < 2.7.4

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2024-4280 White Label CMS [white-label-cms] < 2.7.4 Missing Authorization Medium 5.3 < 2.7.4 2.7.4 2024-05-09

CVE-2024-4280

The White Label CMS plugin for WordPress contains a capability check flaw in its reset_plugin function that affects versions 2.7.3 and earlier, allowing unauthenticated attackers to reset plugin settings without proper authorization. The vulnerability stems from inadequate permission validation on the function responsible for resetting configurations. An attacker could exploit this flaw to modify or reset critical plugin data without authentication. The issue was addressed in version 2.7.4.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.