CVE-2024-0248
WordPress vulnerability analysis and mitigation

Overview

The EazyDocs WordPress plugin before version 2.4.0 reintroduced a previously fixed vulnerability (CVE-2023-6029) in version 2.3.8. This security issue was discovered and disclosed in January 2024, affecting the EazyDocs plugin for WordPress. The vulnerability received a CVSS v3.1 base score of 4.3 (MEDIUM) (NVD).

Technical details

The vulnerability allows any authenticated users, including those with subscriber-level privileges, to perform unauthorized actions such as deleting arbitrary posts and managing documents/sections. The issue was partially addressed in version 2.3.9, but some functionality remained exploitable. The vulnerability is classified as a Broken Access Control issue (OWASP Top 10 A5) and is categorized under CWE-862 (WPScan).

Impact

When exploited, this vulnerability enables authenticated users with low-privilege roles (such as subscribers) to perform unauthorized administrative actions, including the deletion of arbitrary posts and the manipulation of document sections. This can lead to content loss and unauthorized modifications to the website's documentation structure (WPScan).

Mitigation and workarounds

Website administrators should immediately upgrade to EazyDocs version 2.4.0 or later, which contains the complete fix for this vulnerability. No alternative workarounds have been published (WPScan).

Additional resources


SourceThis report was generated using AI

Related WordPress vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2025-14977HIGH8.1
  • dokan-lite
NoYesJan 20, 2026
CVE-2025-14348MEDIUM5.3
  • wemail
NoYesJan 20, 2026
CVE-2026-1045MEDIUM4.4
  • viet-contact
NoNoJan 20, 2026
CVE-2026-1042MEDIUM4.4
  • wp-hello-bar
NoNoJan 20, 2026
CVE-2025-12573N/AN/A
  • bookingor
NoNoJan 20, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management