The ZoxPress - The All-In-One WordPress News Theme theme for WordPress is vulnerable to unauthorized modification of data that can lead to privilege escalation due to a missing capability check on the 'backup_options' function in all versions up to, and including, 2.12.0. This makes it possible for authenticated attackers, with Subscriber-level access and above, to update arbitrary options on the WordPress site. This can be leveraged to update the default role for registration to administrator and enable user registration for attackers to gain administrative user access to a vulnerable site.
Metrics
Affected Vendors & Products
References
History
Tue, 25 Feb 2025 04:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Mvpthemes
Mvpthemes zoxpress |
|
CPEs | cpe:2.3:a:mvpthemes:zoxpress:*:*:*:*:*:wordpress:*:* | |
Vendors & Products |
Mvpthemes
Mvpthemes zoxpress |
Wed, 12 Feb 2025 15:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Wed, 12 Feb 2025 04:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | The ZoxPress - The All-In-One WordPress News Theme theme for WordPress is vulnerable to unauthorized modification of data that can lead to privilege escalation due to a missing capability check on the 'backup_options' function in all versions up to, and including, 2.12.0. This makes it possible for authenticated attackers, with Subscriber-level access and above, to update arbitrary options on the WordPress site. This can be leveraged to update the default role for registration to administrator and enable user registration for attackers to gain administrative user access to a vulnerable site. | |
Title | ZoxPress - The All-In-One WordPress News Theme <= 2.12.0 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Options Update | |
Weaknesses | CWE-862 | |
References |
| |
Metrics |
cvssV3_1
|

Status: PUBLISHED
Assigner: Wordfence
Published:
Updated: 2025-02-12T14:47:51.390Z
Reserved: 2025-01-23T16:16:45.264Z
Link: CVE-2024-13653

Updated: 2025-02-12T14:47:31.763Z

Status : Analyzed
Published: 2025-02-12T05:15:11.820
Modified: 2025-02-25T04:00:58.793
Link: CVE-2024-13653

No data.