CVE-2024-10673

Published Nov 9, 2024

Last updated 5 days ago

Overview

Description
The Top Store theme for WordPress is vulnerable to unauthorized arbitrary plugin installation due to a missing capability check on the top_store_install_and_activate_callback() function in all versions up to, and including, 1.5.4. This makes it possible for authenticated attackers, with subscriber-level access and above, to install arbitrary plugins which can contain other exploitable vulnerabilities to elevate privileges and gain remote code execution.
Source
security@wordfence.com
NVD status
Awaiting Analysis

Risk scores

CVSS 3.1

Type
Primary
Base score
8.8
Impact score
5.9
Exploitability score
2.8
Vector string
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Severity
HIGH

Weaknesses

security@wordfence.com
CWE-862

Social media

Hype score
Not currently trending
  1. CVE-2024-10673 (CVSS:8.8, HIGH) is Awaiting Analysis. The Top Store theme for WordPress is vulnerable to unauthorized arbitrary plugin installation due to a missing capabilit..https://t.co/MtDoNbTws3 #cybersecurityawareness #cybersecurity #CVE #infosec #hacker #nvd #mitre

    @cracbot

    14 Nov 2024

    11 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  2. 🚨 CVE-2024-10673 (Published: 2024-11-09) - A high-severity vulnerability in ThemeHunk affects multiple versions. Users are urged to update to the latest release to mitigate risks. For more details, check the changeset: https://t.co/4YK6fU78Yv #WordPress #Security

    @transilienceai

    13 Nov 2024

    13 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  3. 🚨 CVE-2024-10673 (Published: 2024-11-09) - A high-severity vulnerability in ThemeHunk affects multiple versions. Users are urged to update to the latest release to mitigate risks. For more details, check the changeset here: https://t.co/4YK6fU78Yv #WordPress #Security

    @transilienceai

    13 Nov 2024

    1 Impression

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  4. 🚨 CVE-2024-10673 (Published: 2024-11-09) - A high-severity vulnerability in ThemeHunk affects multiple versions. Users are urged to update to the latest version to mitigate risks. For more details, check the changeset here: https://t.co/4YK6fU78Yv #WordPress #SecurityUpdate

    @transilienceai

    13 Nov 2024

    13 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  5. 🚨 CVE-2024-10673 (Published: 2024-11-09) - A high-severity vulnerability in ThemeHunk affects multiple versions. Users are urged to update to the latest version immediately to mitigate risks. For more details, check the changeset: https://t.co/4YK6fU78Yv #WordPress #Security

    @transilienceai

    13 Nov 2024

    1 Impression

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  6. 🚨 CVE-2024-10673 (Published: 2024-11-09) - A high-severity vulnerability in ThemeHunk affects multiple versions. Users are urged to update to the latest version immediately to mitigate risks. For more details, check the changeset: https://t.co/4YK6fU78Yv #WordPress… https://t.co

    @transilienceai

    13 Nov 2024

    1 Impression

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  7. [CVE-2024-10673: HIGH] WordPress Top Store theme has a critical vulnerability in versions up to 1.5.4. Missing capability check allows attackers to install malicious plugins and gain remote code execution.#cybersecurity,#vulnerability https://t.co/Bjeya2uYn7 https://t.co/qnHPYrw4

    @CveFindCom

    9 Nov 2024

    8 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes