8.8
CVE-2024-5324
- EPSS 43.73%
- Veröffentlicht 06.06.2024 02:15:54
- Zuletzt bearbeitet 08.04.2026 17:19:01
- Quelle security@wordfence.com
- CVE-Watchlists
- Unerledigt
XootiX Framework <= Various Plugin Versions - Missing Authorization to Arbitrary Options Update
Multiple plugins for WordPress utilizing the XootiX Framework are vulnerable to unauthorized modification of data due to a missing capability check on the 'import_settings' function in various versions. This makes it possible for authenticated attackers, with Subscriber-level access and above, to change arbitrary options on affected sites. This can be used to enable new user registration and set the default role for new users to Administrator.
Mögliche Gegenmaßnahme
Login & Register Customizer – Popup | Slider | Inline | WooCommerce: Update to version 2.7.3, or a newer patched version
OTP Login & Register Woocommerce: Update to version 2.6.2, or a newer patched version
Side Cart Woocommerce | Woocommerce Cart: Update to version 2.5.1, or a newer patched version
Waitlist Woocommerce ( Back in stock notifier ): Update to version 2.6.1, or a newer patched version
Weitere Schwachstelleninformationen
SystemWordPress Plugin
≫
Produkt
Login & Register Customizer – Popup | Slider | Inline | WooCommerce
Version
2.7.1-2.7.2
SystemWordPress Plugin
≫
Produkt
OTP Login & Register Woocommerce
Version
*-2.6.1
SystemWordPress Plugin
≫
Produkt
Side Cart Woocommerce | Woocommerce Cart
Version
2.5
SystemWordPress Plugin
≫
Produkt
Waitlist Woocommerce ( Back in stock notifier )
Version
*-2.6
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Xootix ≫ Side Cart Woocommerce Version2.5 SwPlatformwordpress
Xootix ≫ Waitlist Woocommerce SwPlatformwordpress Version < 2.6.1
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 43.73% | 0.974 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| security@wordfence.com | 8.8 | 2.8 | 5.9 |
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
|
CWE-862 Missing Authorization
The product does not perform an authorization check when an actor attempts to access a resource or perform an action.
CWE-863 Incorrect Authorization
The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check.