The Trash Duplicate and 301 Redirect plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check on the 'duplicates-action-top' action in all versions up to, and including, 1.9. This makes it possible for unauthenticated attackers to delete arbitrary posts/pages.
Metrics
Affected Vendors & Products
References
History
Wed, 19 Feb 2025 15:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Wed, 19 Feb 2025 07:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | The Trash Duplicate and 301 Redirect plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check on the 'duplicates-action-top' action in all versions up to, and including, 1.9. This makes it possible for unauthenticated attackers to delete arbitrary posts/pages. | |
Title | Trash Duplicate and 301 Redirect <= 1.9 - Missing Authorization to Unauthenticated Arbitrary Post Deletion | |
Weaknesses | CWE-862 | |
References |
| |
Metrics |
cvssV3_1
|

Status: PUBLISHED
Assigner: Wordfence
Published: 2025-02-19T07:32:14.346Z
Updated: 2025-02-19T14:34:14.405Z
Reserved: 2025-01-16T15:47:36.339Z
Link: CVE-2024-13468

Updated: 2025-02-19T14:33:50.366Z

Status : Received
Published: 2025-02-19T08:15:16.027
Modified: 2025-02-19T08:15:16.027
Link: CVE-2024-13468

No data.