VulnerAlert



ANDROID
APPS
CLOUD
WORDPRESS
28-05-2025 14:44

CVE-2025-4683 Vulnerabilidad documentada

4.3 MEDIUM
Tags
#wordpress
#android
#plugin
#data
#cloud
#apps
#attackers
#authenticated
#vulnerable
#attack
#access
#unauthorized
Descripción
The MStore API – Create Native Android & iOS Apps On The Cloud plugin for WordPress is vulnerable to unauthorized modification of data due a missing capability check on the create_blog function in all versions up to, and including, 4.17.5. This makes it possible authenticated attackers, with Subscriber-level access above, create new posts.
https://plugins.trac.wordpress.org/browser/mstore-api/tags/4.17.5/controllers/helpers/blog-helper.php#L24
https://plugins.trac.wordpress.org/browser/mstore-api/tags/4.17.5/controllers/helpers/blog-helper.php#L46
https://plugins.trac.wordpress.org/changeset/3293669/
https://www.wordfence.com/threat-intel/vulnerabilities/id/b335bd15-7af7-4d8b-ad01-b1d9e76beb53?source=cve
Referencia
Link externo
Ver detalles

Fuente
https://nvd.nist.gov/vuln/detail/CVE-2025-4683
Resultados similares
Coincidentes en almenos en 50% de los tags
02-06-2025 CVE-2025-20297
In Splunk Enterprise versions below 9.4.2, 9.3.4 and 9.2.6, and Splunk Cloud Platform versions ...
Ver información
02-06-2025 CVE-2023-7151
The Product Enquiry for WooCommerce WordPress plugin before 3.2 does not sanitise and escape th...
Ver información
Icons made by Freepik from www.flaticon.com
Este Proyecto fue cofinanciado por el Consejo Nacional de Ciencia y Tecnología (CONACYT) a través del PROINNOVA 2021/2023
Proyecto realizado por