The Swift Framework plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the sf_edit_directory_item() function in all versions up to, and including, 2.7.31. This makes it possible for unauthenticated attackers to update arbitrary posts with arbitrary content. Unfortunately, we did not receive a response from the vendor to send over the vulnerability details.
Metrics
Affected Vendors & Products
References
History
Thu, 26 Feb 2026 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Swift Ideas
Swift Ideas swift Framework |
|
| CPEs | cpe:2.3:a:swift_ideas:swift_framework:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Swift Ideas
Swift Ideas swift Framework |
|
| Metrics |
ssvc
|
Status: PUBLISHED
Assigner: Wordfence
Published:
Updated: 2024-08-01T20:26:56.925Z
Reserved: 2024-04-17T13:26:55.185Z
Link: CVE-2024-3915
Updated: 2024-08-01T20:26:56.925Z
Status : Awaiting Analysis
Published: 2024-05-14T15:42:34.610
Modified: 2024-11-21T09:30:41.487
Link: CVE-2024-3915
No data.
OpenCVE Enrichment
No data.