CVE-2024-0839

The FeedWordPress plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 2022.0222 due to missing validation on the user controlled 'guid' key. This makes it possible for unauthenticated attackers to view draft posts that may contain sensitive information.
Configurations

Configuration 1 (hide)

cpe:2.3:a:feedwordpress_project:feedwordpress:*:*:*:*:*:wordpress:*:*

History

11 Mar 2025, 13:25

Type Values Removed Values Added
CPE cpe:2.3:a:feedwordpress_project:feedwordpress:*:*:*:*:*:wordpress:*:*
First Time Feedwordpress Project
Feedwordpress Project feedwordpress
CWE CWE-639
References () https://wordpress.org/plugins/feedwordpress/ - () https://wordpress.org/plugins/feedwordpress/ - Product
References () https://www.wordfence.com/threat-intel/vulnerabilities/id/1ead46fd-5744-4fbb-9efd-980f9216abbc?source=cve - () https://www.wordfence.com/threat-intel/vulnerabilities/id/1ead46fd-5744-4fbb-9efd-980f9216abbc?source=cve - Third Party Advisory

Information

Published : 2024-03-13 16:15

Updated : 2025-03-11 13:25


NVD link : CVE-2024-0839

Mitre link : CVE-2024-0839

CVE.ORG link : CVE-2024-0839


JSON object : View

Products Affected

feedwordpress_project

  • feedwordpress
CWE
CWE-639

Authorization Bypass Through User-Controlled Key