9.8
CVE-2024-11103
- EPSS 0.16%
- Veröffentlicht 28.11.2024 10:15:06
- Zuletzt bearbeitet 11.04.2025 14:56:31
- Quelle security@wordfence.com
- CVE-Watchlists
- Unerledigt
Contest Gallery <= 24.0.7 - Unauthenticated Arbitrary Password Reset to Privilege Escalation/Account Takeover
The Contest Gallery plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 24.0.7. This is due to the plugin not properly validating a user's identity prior to updating their password. This makes it possible for unauthenticated attackers to change arbitrary user's passwords, including administrators, and leverage that to gain access to their account.
Mögliche Gegenmaßnahme
Contest Gallery – Upload & Vote Photos, Media, Sell with PayPal & Stripe: Update to version 24.0.8, or a newer patched version
Verknüpft mit AI von unstrukturierten Daten zu bestehenden CPE der NVD
Weitere Schwachstelleninformationen
SystemWordPress Plugin
≫
Produkt
Contest Gallery – Upload & Vote Photos, Media, Sell with PayPal & Stripe
Version
*-24.0.7
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Contest-gallery ≫ Contest Gallery SwPlatformwordpress Version < 24.0.8
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.16% | 0.369 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| security@wordfence.com | 9.8 | 3.9 | 5.9 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
|
CWE-640 Weak Password Recovery Mechanism for Forgotten Password
The product contains a mechanism for users to recover or change their passwords without knowing the original password, but the mechanism is weak.