The My Contador lesr plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the exportar_registros() function in all versions up to, and including, 2.0. This makes it possible for unauthenticated attackers to export user data.
Metrics
Affected Vendors & Products
References
History
Tue, 26 Nov 2024 18:00:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Nes360
Nes360 my Contador Lesr |
|
CPEs | cpe:2.3:a:nes360:my_contador_lesr:*:*:*:*:*:wordpress:*:* | |
Vendors & Products |
Nes360
Nes360 my Contador Lesr |
Thu, 21 Nov 2024 12:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Thu, 21 Nov 2024 05:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | The My Contador lesr plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the exportar_registros() function in all versions up to, and including, 2.0. This makes it possible for unauthenticated attackers to export user data. | |
Title | My Contador lesr <= 2.0 - Missing Authorization to Unauthenticated User Registration CSV Export | |
Weaknesses | CWE-862 | |
References |
| |
Metrics |
cvssV3_1
|
MITRE
Status: PUBLISHED
Assigner: Wordfence
Published: 2024-11-21T05:33:50.921Z
Updated: 2024-11-21T11:40:10.945Z
Reserved: 2024-11-18T15:32:46.901Z
Link: CVE-2024-11334
Vulnrichment
Updated: 2024-11-21T11:34:34.988Z
NVD
Status : Analyzed
Published: 2024-11-21T11:15:24.947
Modified: 2024-11-26T17:33:49.477
Link: CVE-2024-11334
Redhat
No data.