8.8

CVE-2024-5324

XootiX Framework <= Various Plugin Versions - Missing Authorization to Arbitrary Options Update

XootiX Framework <= Various Plugin Versions - Missing Authorization to Arbitrary Options Update

Multiple plugins for WordPress utilizing the XootiX Framework are vulnerable to unauthorized modification of data due to a missing capability check on the 'import_settings' function in various versions. This makes it possible for authenticated attackers, with Subscriber-level access and above, to change arbitrary options on affected sites. This can be used to enable new user registration and set the default role for new users to Administrator.
Mögliche Gegenmaßnahme
Login & Register Customizer – Popup | Slider | Inline | WooCommerce: Update to version 2.7.3, or a newer patched version
OTP Login & Register Woocommerce: Update to version 2.6.2, or a newer patched version
Side Cart Woocommerce | Woocommerce Cart: Update to version 2.5.1, or a newer patched version
Waitlist Woocommerce ( Back in stock notifier ): Update to version 2.6.1, or a newer patched version
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
XootixSide Cart Woocommerce Version2.5 SwPlatformwordpress
XootixWaitlist Woocommerce SwPlatformwordpress Version < 2.6.1
Weitere Schwachstelleninformationen
SystemWordPress Plugin
Produkt Login & Register Customizer – Popup | Slider | Inline | WooCommerce
Version 2.7.1-2.7.2
SystemWordPress Plugin
Produkt OTP Login & Register Woocommerce
Version *-2.6.1
SystemWordPress Plugin
Produkt Side Cart Woocommerce | Woocommerce Cart
Version 2.5
SystemWordPress Plugin
Produkt Waitlist Woocommerce ( Back in stock notifier )
Version *-2.6
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 1.51% 0.71
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
security@wordfence.com 8.8 2.8 5.9
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CWE-862 Missing Authorization

The product does not perform an authorization check when an actor attempts to access a resource or perform an action.

CWE-863 Incorrect Authorization

The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check.

https://plugins.trac.wordpress.org/browser/easy-login-woocommerce/trunk/includes/xoo-framework/admin/class-xoo-admin-settings.php#L83
Patch
https://plugins.trac.wordpress.org/changeset/3093994/
Patch
https://www.wordfence.com/threat-intel/vulnerabilities/id/005a27c6-b9eb-466c-b0c3-ce52c25bb321?source=cve
Third Party Advisory
https://plugins.trac.wordpress.org/browser/side-cart-woocommerce/trunk/includes/xoo-framework/admin/class-xoo-admin-settings.php#L83
https://plugins.trac.wordpress.org/changeset/3111541/
https://plugins.trac.wordpress.org/changeset/3115392/mobile-login-woocommerce/trunk?contextall=1&old=3084918&old_path=%2Fmobile-login-woocommerce%2Ftrunk
https://plugins.trac.wordpress.org/changeset/3117332/
https://www.wordfence.com/threat-intel/vulnerabilities/id/005a27c6-b9eb-466c-b0c3-ce52c25bb321
Third Party Advisory