Medium severity4.3NVD Advisory· Published May 2, 2024· Updated Apr 8, 2026
CVE-2024-3607
CVE-2024-3607
Description
The PropertyHive plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check on the delete_key_date() function in all versions up to, and including, 2.0.12. This makes it possible for authenticated attackers, with subscriber-level access and above, to delete arbitrary posts
Affected products
1- cpe:2.3:a:wp-property-hive:propertyhive:*:*:*:*:*:wordpress:*:*Range: <2.0.13
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
2- plugins.trac.wordpress.org/changesetnvdPatch
- www.wordfence.com/threat-intel/vulnerabilities/id/d8d52ced-807b-48c0-bb7a-e40d143ae5d3nvdThird Party Advisory
News mentions
0No linked articles in our index yet.