CVE-2024-3915 affects the Swift Framework plugin for WordPress, specifically versions up to and including 2.7.31. This vulnerability allows unauthenticated attackers to modify arbitrary posts with arbitrary content due to a missing capability check in the sf_edit_directory_item() function. The vulnerability has a CVSS score of 5.3 (Medium), indicating a low-complexity attack that can be executed over the network without user interaction, leading to data integrity compromise. While the EPSS score is low, the potential for unauthenticated content modification is significant. Currently, there is no evidence of active exploitation, nor is exploit code available in Metasploit, Nuclei, or ExploitDB. The CVE has received no community discussion or media coverage, suggesting low public awareness at this time.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| Swift Ideas | Swift Framework | >= 0, <= 2.7.31CNA affecteddefault unaffected |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.