CVE-2024-13420 is a medium-severity vulnerability affecting multiple WordPress plugins and themes developed by G5Plus, including g5plus april, auteur, benaa, and beyot. It allows authenticated attackers with subscriber-level access to reset and modify certain plugin/theme settings due to missing capability checks on several AJAX actions. The vulnerability has a CVSS score of 4.3, indicating a low attack complexity and impact limited to integrity, with no confidentiality or availability impact. There is currently no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 5.1CPE matchmatch criteria | cpe:2.3:a:g5plus:april:*:*:*:*:*:wordpress:*:* | ||
<= 7.1CPE matchmatch criteria | cpe:2.3:a:g5plus:auteur:*:*:*:*:*:wordpress:*:* | ||
<= 4.0.0CPE matchmatch criteria | cpe:2.3:a:g5plus:benaa:*:*:*:*:*:wordpress:*:* | ||
<= 6.0.6CPE matchmatch criteria | cpe:2.3:a:g5plus:beyot:*:*:*:*:*:wordpress:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.