The WP Accessibility Helper (WAH) plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'save_contrast_variations' and 'save_empty_contrast_variations' functions in all versions up to, and including, 0.6.2.8. This makes it possible for authenticated attackers, with Subscriber-level access and above, to edit or delete contrast settings. Please note these issues were patched in 0.6.2.8, though it broke functionality and the vendor has not responded to our follow-ups.
History

Fri, 04 Oct 2024 13:15:00 +0000

Type Values Removed Values Added
First Time appeared Volkov
Volkov wp Accessibility Helper
CPEs cpe:2.3:a:volkov:wp_accessibility_helper:*:*:*:*:*:wordpress:*:*
Vendors & Products Volkov
Volkov wp Accessibility Helper

Thu, 29 Aug 2024 20:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 29 Aug 2024 05:45:00 +0000

Type Values Removed Values Added
Description The WP Accessibility Helper (WAH) plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'save_contrast_variations' and 'save_empty_contrast_variations' functions in all versions up to, and including, 0.6.2.8. This makes it possible for authenticated attackers, with Subscriber-level access and above, to edit or delete contrast settings. Please note these issues were patched in 0.6.2.8, though it broke functionality and the vendor has not responded to our follow-ups.
Title WP Accessibility Helper <= 0.6.2.8 - Missing Authorization to Authenticated (Subscriber+) Limited Settings Update
Weaknesses CWE-862
References
Metrics cvssV3_1

{'score': 5.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L'}


cve-icon MITRE

Status: PUBLISHED

Assigner: Wordfence

Published: 2024-08-29T05:30:57.345Z

Updated: 2024-08-29T14:04:01.371Z

Reserved: 2024-06-13T19:25:37.920Z

Link: CVE-2024-5987

cve-icon Vulnrichment

Updated: 2024-08-29T14:03:57.745Z

cve-icon NVD

Status : Analyzed

Published: 2024-08-29T11:15:27.977

Modified: 2024-10-04T12:56:47.997

Link: CVE-2024-5987

cve-icon Redhat

No data.