VYPR
High severity8.1NVD Advisory· Published Feb 12, 2025· Updated Jun 17, 2026

CVE-2024-13654

CVE-2024-13654

Description

The ZoxPress - The All-In-One WordPress News Theme theme for WordPress is vulnerable to unauthorized modification of data that can lead to a denial of service due to a missing capability check on the 'reset_options' function in all versions up to, and including, 2.12.0. This makes it possible for authenticated attackers, with Subscriber-level access and above, to delete arbitrary option values on the WordPress site. This can be leveraged to delete an option that would create an error on the site and deny service to legitimate users.

Affected products

4
  • WordPress/Zoxpressllm-fuzzy2 versions
    <=2.12.0+ 1 more
    • (no CPE)range: <=2.12.0
    • (no CPE)
  • MVPThemes/ZoxPress - The All-In-One WordPress News Themev5
    Range: 0
  • cpe:2.3:a:mvpthemes:zoxpress:*:*:*:*:*:wordpress:*:*
    Range: <2.12.1

Patches

Vulnerability mechanics

References

2

News mentions

0

No linked articles in our index yet.