Medium severity6.5NVD Advisory· Published Jan 20, 2024· Updated Apr 8, 2026
CVE-2024-0679
CVE-2024-0679
Description
The ColorMag theme for WordPress is vulnerable to unauthorized access due to a missing capability check on the plugin_action_callback() function in all versions up to, and including, 3.1.2. This makes it possible for authenticated attackers, with subscriber-level access and above, to install and activate arbitrary plugins.
Affected products
1Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
3- themes.trac.wordpress.org/changesetnvdPatch
- www.wordfence.com/threat-intel/vulnerabilities/id/e982d457-29db-468f-88c3-5afe04002dcfnvdThird Party Advisory
- themes.trac.wordpress.org/browser/colormag/3.1.2/functions.phpnvdIssue Tracking
News mentions
0No linked articles in our index yet.