Vulnerability Description
The Sparkle Demo Importer plugin for WordPress is vulnerable to unauthorized database reset and demo data import due to a missing capability check on the multiple functions in all versions up to and including 1.4.7. This makes it possible for authenticated attackers, with Subscriber-level access and above, to delete all posts, pages, and uploaded files, as well as download and install a limited set of demo plugins.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Wpneuron | Sparkle Demo Importer | < 1.4.8 |
Related Weaknesses (CWE)
References
- https://plugins.trac.wordpress.org/browser/sparkle-demo-importer/tags/1.4.7/sparProduct
- https://plugins.trac.wordpress.org/browser/sparkle-demo-importer/tags/1.4.7/sparProduct
- https://plugins.trac.wordpress.org/browser/sparkle-demo-importer/tags/1.4.7/sparProduct
- https://plugins.trac.wordpress.org/browser/sparkle-demo-importer/tags/1.4.7/sparProduct
- https://plugins.trac.wordpress.org/browser/sparkle-demo-importer/tags/1.4.7/sparProduct
- https://plugins.trac.wordpress.org/browser/sparkle-demo-importer/tags/1.4.7/sparProduct
- https://plugins.trac.wordpress.org/browser/sparkle-demo-importer/tags/1.4.7/sparProduct
- https://plugins.trac.wordpress.org/browser/sparkle-demo-importer/tags/1.4.7/sparProduct
- https://www.wordfence.com/threat-intel/vulnerabilities/id/8f411d17-5b0d-4a4a-afaThird Party Advisory
- https://plugins.trac.wordpress.org/browser/sparkle-demo-importer/tags/1.4.7/sparProduct
- https://plugins.trac.wordpress.org/browser/sparkle-demo-importer/tags/1.4.7/sparProduct
- https://plugins.trac.wordpress.org/browser/sparkle-demo-importer/tags/1.4.7/sparProduct
- https://plugins.trac.wordpress.org/browser/sparkle-demo-importer/tags/1.4.7/sparProduct
- https://plugins.trac.wordpress.org/browser/sparkle-demo-importer/tags/1.4.7/sparProduct
- https://plugins.trac.wordpress.org/browser/sparkle-demo-importer/tags/1.4.7/sparProduct
FAQ
What is CVE-2024-6120?
CVE-2024-6120 is a vulnerability with a CVSS score of 6.5 (MEDIUM). The Sparkle Demo Importer plugin for WordPress is vulnerable to unauthorized database reset and demo data import due to a missing capability check on the multiple functions in all versions up to and i...
How severe is CVE-2024-6120?
CVE-2024-6120 has been rated MEDIUM with a CVSS base score of 6.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2024-6120?
Check the references section above for vendor advisories and patch information. Affected products include: Wpneuron Sparkle Demo Importer.