8.8
CVE-2024-6698
- EPSS 0.42%
- Veröffentlicht 01.08.2024 04:15:04
- Zuletzt bearbeitet 23.11.2024 00:44:15
- Quelle security@wordfence.com
- CVE-Watchlists
- Unerledigt
FundEngine – Donation and Crowdfunding Platform <= 1.7.0 - Authenticated (Subscriber+) Privilege Escalation
The FundEngine plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including, 1.7.0. This is due to the plugin not properly verifying user meta updated through the update_user_meta function. This makes it possible for authenticated attackers, with subscriber-level access and above, to update their user meta which can be leveraged to update their capabilities to gain administrator access.
Mögliche Gegenmaßnahme
FundEngine – Donation and Crowdfunding Platform: Update to version 1.7.1, or a newer patched version
Weitere Schwachstelleninformationen
SystemWordPress Plugin
≫
Produkt
FundEngine – Donation and Crowdfunding Platform
Version
*-1.7.0
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Wpmet ≫ Fundengine SwPlatformwordpress Version < 1.7.1
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.42% | 0.615 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| security@wordfence.com | 8.8 | 2.8 | 5.9 |
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
|
CWE-862 Missing Authorization
The product does not perform an authorization check when an actor attempts to access a resource or perform an action.