Description
The Puzzles | WP Magazine / Review with Store WordPress Theme + RTL theme for WordPress is vulnerable to Stored Cross-Site Scripting due to a missing capability check on the 'theme_options_ajax_post_action' AJAX action in all versions up to, and including, 4.2.4. This makes it possible for authenticated attackers, with Subscriber-level access and above, to update the plugin's settings and inject malicious web scripts. The developer opted to remove the software from the repository, so an update is not available and it is recommended to find a replacement software.
INFO
Published Date :
2025-02-12T04:22:13.636Z
Last Modified :
2025-02-12T14:54:53.265Z
Source :
Wordfence
AFFECTED PRODUCTS
The following products are affected by CVE-2024-13769 vulnerability.
| Vendors | Products |
|---|---|
| Themerex |
|
REFERENCES
Here, you will find a curated list of external links that provide in-depth information to CVE-2024-13769.