Missing Authorization vulnerability in HM Plugin WordPress Stripe Donation and Payment Plugin allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WordPress Stripe Donation and Payment Plugin: from n/a through 3.2.3.
History

Wed, 06 Nov 2024 23:30:00 +0000

Type Values Removed Values Added
First Time appeared Hmplugin aidwp
CPEs cpe:2.3:a:hmplugin:aidwp:*:*:*:*:*:wordpress:*:*
Vendors & Products Hmplugin aidwp

Tue, 29 Oct 2024 20:15:00 +0000

Type Values Removed Values Added
First Time appeared Hmplugin
Hmplugin accept Stripe Donation - Aidwp
CPEs cpe:2.3:a:hmplugin:accept_stripe_donation_-_aidwp:*:*:*:*:*:wordpress:*:*
Vendors & Products Hmplugin
Hmplugin accept Stripe Donation - Aidwp
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 29 Oct 2024 16:45:00 +0000

Type Values Removed Values Added
Description Missing Authorization vulnerability in HM Plugin WordPress Stripe Donation and Payment Plugin allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WordPress Stripe Donation and Payment Plugin: from n/a through 3.2.3.
Title WordPress AidWP plugin <= 3.2.3 - Broken Access Control vulnerability
Weaknesses CWE-862
References
Metrics cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published: 2024-10-29T16:36:10.211Z

Updated: 2024-10-29T19:39:36.671Z

Reserved: 2024-10-24T07:26:19.562Z

Link: CVE-2024-50459

cve-icon Vulnrichment

Updated: 2024-10-29T19:39:28.586Z

cve-icon NVD

Status : Analyzed

Published: 2024-10-29T17:15:04.423

Modified: 2024-11-06T23:11:17.687

Link: CVE-2024-50459

cve-icon Redhat

No data.