Medium severity5.3NVD Advisory· Published Jan 18, 2025· Updated Jun 17, 2026
CVE-2024-12071
CVE-2024-12071
Description
The Evergreen Content Poster – Auto Post and Schedule Your Best Content to Social Media plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check on the delete_network_post() function in all versions up to, and including, 1.4.4. This makes it possible for unauthenticated attackers to delete arbitrary posts and pages.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3- cpe:2.3:a:evergreencontentposter:evergreen_content_poster:*:*:*:*:*:wordpress:*:*Range: <1.4.5
- Range: <=1.4.4
- evergreencontentposter/Evergreen Content Poster – Auto Post and Schedule Your Best Content to Social Mediav5Range: 0
Patches
Vulnerability mechanics
References
4- plugins.trac.wordpress.org/changesetnvdPatch
- www.wordfence.com/threat-intel/vulnerabilities/id/aa07f48f-370f-4985-a6fc-a94ed5c59ed4nvdThird Party Advisory
- plugins.trac.wordpress.org/browser/evergreen-content-poster/trunk/admin/class-evergreen_content_poster-admin.phpnvdProduct
- plugins.trac.wordpress.org/browser/evergreen-content-poster/trunk/includes/class-evergreen_content_poster.phpnvdProduct
News mentions
0No linked articles in our index yet.