Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-51128 | The Custom Related Posts plugin for WordPress is vulnerable to unauthorized access & modification of data due to a missing capability check on three AJAX actions in all versions up to, and including, 1.7.3. This makes it possible for authenticated attackers, with Subscriber-level access and above, to search posts and link/unlink relations. |
Sat, 12 Jul 2025 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
epss
|
epss
|
Fri, 21 Feb 2025 16:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Brechtvds
Brechtvds custom Related Posts |
|
| CPEs | cpe:2.3:a:brechtvds:custom_related_posts:*:*:*:*:*:wordpress:*:* | |
| Vendors & Products |
Brechtvds
Brechtvds custom Related Posts |
Mon, 03 Feb 2025 17:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Sat, 01 Feb 2025 07:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The Custom Related Posts plugin for WordPress is vulnerable to unauthorized access & modification of data due to a missing capability check on three AJAX actions in all versions up to, and including, 1.7.3. This makes it possible for authenticated attackers, with Subscriber-level access and above, to search posts and link/unlink relations. | |
| Title | Custom Related Posts <= 1.7.3 - Missing Authorization to Authenticated (Subscriber+) Private Post Search and Relation Updates | |
| Weaknesses | CWE-862 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: Wordfence
Published:
Updated: 2026-04-08T16:48:29.150Z
Reserved: 2024-12-19T21:19:58.518Z
Link: CVE-2024-12825
Updated: 2025-02-03T16:07:46.488Z
Status : Analyzed
Published: 2025-02-01T08:15:07.337
Modified: 2025-02-21T15:34:58.803
Link: CVE-2024-12825
No data.
OpenCVE Enrichment
No data.
EUVD