8.8
CVE-2024-5324
- EPSS 37.22%
- Published 06.06.2024 02:15:54
- Last modified 21.11.2024 09:47:25
- Source security@wordfence.com
- Teams watchlist Login
- Open Login
The Login/Signup Popup ( Inline Form + Woocommerce ) plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'import_settings' function in versions 2.7.1 to 2.7.2. This makes it possible for authenticated attackers, with Subscriber-level access and above, to change arbitrary options on affected sites. This can be used to enable new user registration and set the default role for new users to Administrator.
Data is provided by the National Vulnerability Database (NVD)
Xootix ≫ Login/signup Popup Version2.7.1 SwPlatformwordpress
Xootix ≫ Login/signup Popup Version2.7.2 SwPlatformwordpress
Xootix ≫ Otp Login Woocommerce & Gravity Forms SwPlatformwordpress Version < 2.6.2
Xootix ≫ Side Cart Woocommerce Version2.5 SwPlatformwordpress
Xootix ≫ Waitlist Woocommerce SwPlatformwordpress Version < 2.6.1
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
Type | Source | Score | Percentile |
---|---|---|---|
EPSS | FIRST.org | 37.22% | 0.97 |
Source | Base Score | Exploit Score | Impact Score | Vector string |
---|---|---|---|---|
security@wordfence.com | 8.8 | 2.8 | 5.9 |
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
|
CWE-863 Incorrect Authorization
The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check.