8.8
CVE-2024-5324
- EPSS 43.73%
- Veröffentlicht 06.06.2024 02:15:54
- Zuletzt bearbeitet 21.11.2024 09:47:25
- Quelle security@wordfence.com
- CVE-Watchlists
- Unerledigt
XootiX Framework <= Various Plugin Versions - Missing Authorization to Arbitrary Options Update
The Login/Signup Popup ( Inline Form + Woocommerce ) plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'import_settings' function in versions 2.7.1 to 2.7.2. This makes it possible for authenticated attackers, with Subscriber-level access and above, to change arbitrary options on affected sites. This can be used to enable new user registration and set the default role for new users to Administrator.
Mögliche Gegenmaßnahme
Login & Register Customizer – Popup | Slider | Inline | WooCommerce: Update to version 2.7.3, or a newer patched version
OTP Login Woocommerce (Login with OTP): Update to version 2.6.2, or a newer patched version
Side Cart Woocommerce | Woocommerce Cart: Update to version 2.5.1, or a newer patched version
Waitlist Woocommerce ( Back in stock notifier ): Update to version 2.6.1, or a newer patched version
Weitere Schwachstelleninformationen
SystemWordPress Plugin
≫
Produkt
Login & Register Customizer – Popup | Slider | Inline | WooCommerce
Version
2.7.1 - 2.7.2
SystemWordPress Plugin
≫
Produkt
OTP Login Woocommerce (Login with OTP)
Version
* - 2.6.1
SystemWordPress Plugin
≫
Produkt
Side Cart Woocommerce | Woocommerce Cart
Version
2.5
SystemWordPress Plugin
≫
Produkt
Waitlist Woocommerce ( Back in stock notifier )
Version
* - 2.6
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Xootix ≫ Login/signup Popup Version2.7.1 SwPlatformwordpress
Xootix ≫ Login/signup Popup Version2.7.2 SwPlatformwordpress
Xootix ≫ Otp Login Woocommerce & Gravity Forms SwPlatformwordpress Version < 2.6.2
Xootix ≫ Side Cart Woocommerce Version2.5 SwPlatformwordpress
Xootix ≫ Waitlist Woocommerce SwPlatformwordpress Version < 2.6.1
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 43.73% | 0.974 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| security@wordfence.com | 8.8 | 2.8 | 5.9 |
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
|
CWE-863 Incorrect Authorization
The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check.