The Workreap WordPress theme before 2.6.4 does not verify that an addon service belongs to the user issuing the request, or indeed that it is an addon service, when processing the workreap_addons_service_remove action, allowing any user to delete any post by knowing or guessing the id.

No history.

cve-icon MITRE


Assigner: WPScan


Updated: 2024-08-03T01:34:49.603Z

Reserved: 2022-11-30T19:00:06.582Z

Link: CVE-2022-4239

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2022-12-26T13:15:13.840

Modified: 2024-11-21T07:34:51.060

Link: CVE-2022-4239

cve-icon Redhat

No data.