AUGUST 4, 2026
Live Feed
Back to database
Case File

CVE-2024-0248

MEDIUM · CVSS 4.3 EPSS 0.42%

Source: NVD + CISA KEV + EPSS (historical backfill) · Published 2024-02-12 · Last synced 2026-08-04

CyberRota Analysis

This is a medium severity vulnerability with a CVSS score of 4.3. It affects WordPress. Exploitation may require the attacker to be authenticated.

CVE
CVE-2024-0248
Severity
MEDIUM
CVSS
4.3
EPSS
0.42%
WordPress

Original NVD Description

The EazyDocs WordPress plugin before 2.4.0 re-introduced CVE-2023-6029 (https://wpscan.com/vulnerability/7a0aaf85-8130-4fd7-8f09-f8edc929597e/) in 2.3.8, allowing any authenticated users, such as subscriber to delete arbitrary posts, as well as add and delete documents/sections. The issue was partially fixed in 2.3.9.

Related CVEs

Other vulnerabilities affecting the same vendor(s)