Security Advisory

CVE-2024-13423

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2025-03-05 11:22:09
Last updated 2026-04-08 16:41:03
Assigner Wordfence
CVSS score 5.3
State PUBLISHED

Description

The Sparkling theme for WordPress is vulnerable to unauthorized plugin activation/deactivation due to a missing capability check on the 'sparkling_activate_plugin' and 'sparkling_deactivate_plugin' functions in versions up to, and including, 2.4.9. This makes it possible for unauthenticated attackers to activate/deactivate arbitrary plugins.