CVE-2024-4280: Videousermanuals White Label CMS

Medium severity, CVSS 5.3. EPSS: 0.4% chance of exploitation in the next 30 days.

The White Label CMS plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the reset_plugin function in all versions up to, and including, 2.7.3. This makes it possible for unauthenticated attackers to reset plugin settings.

Affected products

Published 2024-05-14. Last modified 2026-06-17.