Multiple plugins and/or themes for WordPress using Smart Framework are vulnerable to Stored Cross-Site Scripting due to a missing capability check on the saveOptions() and importThemeOptions() functions in various versions. This makes it possible for authenticated attackers, with Subscriber-level access and above, to update the plugin's settings which includes custom JavaScript that is enabled site-wide. This issue was escalated to Envato over two months from the date of this disclosure and the issue is still vulnerable.
Metrics
Affected Vendors & Products
References
History
Fri, 02 May 2025 03:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | Multiple plugins and/or themes for WordPress using Smart Framework are vulnerable to Stored Cross-Site Scripting due to a missing capability check on the saveOptions() and importThemeOptions() functions in various versions. This makes it possible for authenticated attackers, with Subscriber-level access and above, to update the plugin's settings which includes custom JavaScript that is enabled site-wide. This issue was escalated to Envato over two months from the date of this disclosure and the issue is still vulnerable. | |
Title | Smart Framework <= Multiple Plugins - Missing Authorization to Authenticated (Subscriber+) Stored Cross-Site Scripting | |
Weaknesses | CWE-862 | |
References |
| |
Metrics |
cvssV3_1
|

Status: PUBLISHED
Assigner: Wordfence
Published: 2025-05-02T03:21:17.035Z
Updated: 2025-05-02T15:00:22.379Z
Reserved: 2025-01-15T18:32:29.194Z
Link: CVE-2024-13419

No data.

Status : Awaiting Analysis
Published: 2025-05-02T04:15:45.873
Modified: 2025-05-02T13:52:51.693
Link: CVE-2024-13419

No data.