Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-33752 | The Classified Listing – Classified ads & Business Directory Plugin plugin for WordPress is vulnerable to unauthorized modification of data that can lead to privilege escalation due to a misconfigured check on the 'rtcl_import_settings' function in all versions up to, and including, 3.1.15.1. This makes it possible for authenticated attackers, with Subscriber-level access and above, to update limited arbitrary options on the WordPress site. This can be leveraged to update the Subscriber role with Administrator-level capabilities to gain administrative user access to a vulnerable site. The vulnerability is limited in that the option updated must have a value that is an array. |
Tue, 19 Nov 2024 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Techlabpro1
Techlabpro1 classified Listing Plugin |
|
| CPEs | cpe:2.3:a:techlabpro1:classified_listing_plugin:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Techlabpro1
Techlabpro1 classified Listing Plugin |
|
| Metrics |
ssvc
|
Tue, 19 Nov 2024 11:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The Classified Listing – Classified ads & Business Directory Plugin plugin for WordPress is vulnerable to unauthorized modification of data that can lead to privilege escalation due to a misconfigured check on the 'rtcl_import_settings' function in all versions up to, and including, 3.1.15.1. This makes it possible for authenticated attackers, with Subscriber-level access and above, to update limited arbitrary options on the WordPress site. This can be leveraged to update the Subscriber role with Administrator-level capabilities to gain administrative user access to a vulnerable site. The vulnerability is limited in that the option updated must have a value that is an array. | |
| Title | Classified Listing – Classified ads & Business Directory Plugin <= 3.1.15.1 - Authenticated (Subscriber+) Limited Arbitrary Option Update | |
| Weaknesses | CWE-862 | |
| References |
|
|
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: Wordfence
Published:
Updated: 2026-04-08T16:36:42.302Z
Reserved: 2024-11-13T20:01:13.564Z
Link: CVE-2024-11194
Updated: 2024-11-19T14:21:16.850Z
Status : Deferred
Published: 2024-11-19T12:15:16.497
Modified: 2026-04-15T00:35:42.020
Link: CVE-2024-11194
No data.
OpenCVE Enrichment
No data.
EUVD