CVE-2024-1047 affects the Orbit Fox by ThemeIsle plugin for WordPress, specifically versions up to and including 2.10.28. This vulnerability allows unauthenticated attackers to modify connected API keys due to a missing capability check in the register_reference() function. The CVSS score of 5.3 (Medium) indicates a low attack complexity and no user interaction required, with the potential for unauthorized data modification (Integrity impact). There is no confidentiality or availability impact. Currently, there is no evidence of active exploitation, nor is exploit code available in common repositories like Metasploit or ExploitDB. The vulnerability has received minimal community discussion and media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 2.10.28CPE matchmatch criteria | cpe:2.3:a:themeisle:orbit_fox:*:*:*:*:*:wordpress:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.