CVE Radar Logo
CVERadar
CVE Radar Logo
CVERadar

CVE-2024-13643

Medium Severity
SVRS
30/100

CVSSv3
NA/10

EPSS
0.00065/1

CVE-2024-13643 in the Zox News WordPress theme allows unauthorized data modification. This vulnerability affects versions up to 3.17.0, enabling authenticated attackers with subscriber-level access to modify arbitrary WordPress option values. With an SVRS of 30, the risk is moderate, but still requires attention. Attackers could escalate privileges by changing the default user role to Administrator, effectively gaining control of the site. The issue stems from missing capability checks on the backup_options() and reset_options() functions. Furthermore, attackers can delete critical options, potentially causing a denial of service. While the CVSS score is 0, the potential for privilege escalation makes this a significant security risk.

In The Wild
2025-02-11

2025-02-11
Eye Icon
SOCRadar
AI Insight

```markdown

Description

CVE-2024-13643 is a vulnerability affecting the Zox News - Professional WordPress News & Magazine Theme plugin, versions 3.17.0 and earlier. It allows authenticated attackers with Subscriber-level access or higher to modify arbitrary WordPress options due to missing capability checks in the backup_options() and reset_options() functions. This unauthorized data modification can lead to privilege escalation, potentially granting attackers administrative access by manipulating user registration settings. While the CVSS score is 8.8, the SOCRadar Vulnerability Risk Score (SVRS) is 42, suggesting a moderate risk level.

Key Insights

  1. Privilege Escalation: The most critical aspect of this vulnerability is the potential for Subscriber-level users to elevate their privileges to Administrator. By manipulating the default user role and enabling user registration, attackers can create new administrator accounts and gain full control of the WordPress site.

  2. Denial of Service: The vulnerability allows for the deletion of critical WordPress options. Removing these options can cause website malfunctions and errors, leading to a denial of service for legitimate users.

  3. Low SVRS vs High CVSS: While the CVSS indicates a high severity vulnerability, the SVRS of 42 suggests a moderate risk. This discrepancy may be due to the vulnerability requiring authentication (limiting its exploitability) and the absence of active exploitation in the wild detected by SOCRadar's threat intelligence feeds (Social Media, News, Code Repositories, Dark/Deep Web data, and associations with Threat Actors and malware).

Mitigation Strategies

  1. Update the Zox News Theme: The primary mitigation strategy is to update the Zox News - Professional WordPress News & Magazine Theme plugin to a version later than 3.17.0, where the vulnerability is patched.

  2. Restrict User Registration (If Not Needed): If user registration is not required, disable it in the WordPress settings to prevent attackers from exploiting the vulnerability even if they manage to manipulate user registration settings. Navigate to Settings > General and uncheck the box next to "Anyone can register."

  3. Implement a Web Application Firewall (WAF): Deploy a WAF with rules specifically designed to detect and prevent unauthorized access to WordPress options. This will add an additional layer of protection against exploitation attempts.

Additional Information

If users have additional queries regarding this incident, they can use the 'Ask to Analyst' feature, contact SOCRadar directly, or open a support ticket for more information if necessary. ```

Indicators of Compromise

No IOCs found for this CVE

Exploits

No exploits found for this CVE

Enhance Your CVE Management with SOCRadar Vulnerability Intelligence
Get comprehensive CVE details, real-time notifications, and proactive threat management all in one platform.
CVE Details
Access comprehensive CVE information instantly
Real-time Tracking
Subscribe to CVEs and get instant updates
Exploit Analysis
Monitor related APT groups and threats
IOC Tracking
Analyze and track CVE-related IOCs

News

CVE-2024-13643 | MVPThemes Zox News Plugin up to 3.17.0 on WordPress backup_options authorization
vuldb.com2025-02-11
CVE-2024-13643 | MVPThemes Zox News Plugin up to 3.17.0 on WordPress backup_options authorization | A vulnerability classified as problematic has been found in MVPThemes Zox News Plugin up to 3.17.0 on WordPress. This affects the function backup_options. The manipulation leads to missing authorization. This vulnerability is uniquely identified as CVE-2024-13643. It is possible to initiate the attack remotely. There is
vuldb.com
rss
forum
news

Social Media

CVE-2024-13643 (CVSS:8.8, HIGH) is Awaiting Analysis. The Zox News - Professional WordPress News & Magazine Theme plugin for WordPress is vulnerable to unauthorized data modi..https://t.co/APoCBGDt4Q #cybersecurityawareness #cybersecurity #CVE #infosec #hacker #nvd #mitre
0
0
0
CVE-2024-13643 The Zox News - Professional WordPress News & Magazine Theme plugin for WordPress is vulnerable to unauthorized data modification. This vulnerability can lead to privi… https://t.co/x3lVb4KJ2J
0
0
0
[CVE-2024-13643: HIGH] Vulnerability alert: Zox News - Professional WordPress News & Magazine Theme plugin versions up to 3.17.0 susceptible to privilege escalation & denial of service attacks. Attackers with Sub...#cybersecurity,#vulnerability https://t.co/S4bv69t9Ux https://t.co/d6BWXtK6QG
0
0
1

Affected Software

No affected software found for this CVE

References

ReferenceLink
[email protected]https://mvpthemes.com/zoxnews/
[email protected]https://themeforest.net/item/zox-news-professional-wordpress-news-magazine-theme/20381541
[email protected]https://www.wordfence.com/threat-intel/vulnerabilities/id/4adb7436-11e6-4512-b6c9-551402909bf0?source=cve

CWE Details

CWE IDCWE NameDescription
CWE-862Missing AuthorizationThe software does not perform an authorization check when an actor attempts to access a resource or perform an action.

CVE Radar

Real-time CVE Intelligence & Vulnerability Management Platform

CVE Radar provides comprehensive vulnerability intelligence by monitoring CVE databases, security advisories, and threat feeds. Get instant updates on new vulnerabilities, exploit details, and mitigation strategies specific to your assets.

Get Free Vulnerability Intelligence AccessAccess real-time CVE monitoring, exploit analysis, and threat intelligence