The Play.ht – Make Your Blog Posts Accessible With Text to Speech Audio plugin for WordPress is vulnerable to unauthorized access of functionality due to a missing capability check on several functions in all versions up to, and including, 3.6.4. This makes it possible for authenticated attackers, with subscriber access or higher, to delete, retrieve, or modify post metadata, retrieve posts contents of protected posts, modify conversion data and delete article audio.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-16612 | The Play.ht – Make Your Blog Posts Accessible With Text to Speech Audio plugin for WordPress is vulnerable to unauthorized access of functionality due to a missing capability check on several functions in all versions up to, and including, 3.6.4. This makes it possible for authenticated attackers, with subscriber access or higher, to delete, retrieve, or modify post metadata, retrieve posts contents of protected posts, modify conversion data and delete article audio. |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Wed, 08 Apr 2026 17:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Play.ht – Make Your Blog Posts Accessible With Text to Speech Audio <= 3.6.4 - Missing Authorization |
Tue, 15 Apr 2025 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 11 Mar 2025 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Hammadh
Hammadh play.ht |
|
| Weaknesses | CWE-862 | |
| CPEs | cpe:2.3:a:hammadh:play.ht:*:*:*:*:*:wordpress:*:* | |
| Vendors & Products |
Hammadh
Hammadh play.ht |
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: Wordfence
Published:
Updated: 2026-04-08T16:54:17.317Z
Reserved: 2024-01-23T16:47:49.972Z
Link: CVE-2024-0828
Updated: 2024-08-01T18:18:18.628Z
Status : Modified
Published: 2024-03-13T16:15:13.833
Modified: 2026-04-08T18:18:58.727
Link: CVE-2024-0828
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD