CVE-2024-13703

The CRM and Lead Management by vcita plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the vcita_ajax_toggle_ae() function in all versions up to, and including, 2.7.1. This makes it possible for authenticated attackers, with Subscriber-level access and above, to enable and disable plugin widgets.
Configurations

Configuration 1 (hide)

cpe:2.3:a:vcita:crm_and_lead_management_by_vcita:*:*:*:*:*:wordpress:*:*

History

26 May 2025, 02:16

Type Values Removed Values Added
CPE cpe:2.3:a:vcita:crm_and_lead_management_by_vcita:*:*:*:*:*:wordpress:*:*
First Time Vcita crm And Lead Management By Vcita
Vcita
Summary
  • (es) El complemento CRM and Lead Management by vcita para WordPress es vulnerable a la modificación no autorizada de datos debido a la falta de una comprobación de capacidad en la función vcita_ajax_toggle_ae() en todas las versiones hasta la 2.7.1 incluida. Esto permite que atacantes autenticados, con acceso de suscriptor o superior, habiliten y deshabiliten los widgets del plugin.
References () https://plugins.trac.wordpress.org/browser/crm-customer-relationship-management-by-vcita/trunk/vcita-ajax-function.php#L6 - () https://plugins.trac.wordpress.org/browser/crm-customer-relationship-management-by-vcita/trunk/vcita-ajax-function.php#L6 - Product
References () https://www.wordfence.com/threat-intel/vulnerabilities/id/8e8c2aa5-5770-4b88-b415-40c2aff69d84?source=cve - () https://www.wordfence.com/threat-intel/vulnerabilities/id/8e8c2aa5-5770-4b88-b415-40c2aff69d84?source=cve - Third Party Advisory

13 Mar 2025, 02:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-03-13 02:15

Updated : 2025-05-26 02:16


NVD link : CVE-2024-13703

Mitre link : CVE-2024-13703

CVE.ORG link : CVE-2024-13703


JSON object : View

Products Affected

vcita

  • crm_and_lead_management_by_vcita
CWE
CWE-862

Missing Authorization