The Newsletters plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including, 4.9.9.2. This is due to the plugin not restricting what user meta can be updated as screen options. This makes it possible for authenticated attackers, with subscriber-level access and above, to escalate their privileges to that of an administrator. Please note that this only affects users with access to edit/update screen options, which means an administrator would need to grant lower privilege users with access to the Sent & Draft Emails page of the plugin in order for this to be exploited.
Metrics
Affected Vendors & Products
References
History
Thu, 26 Sep 2024 22:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Weaknesses | NVD-CWE-noinfo | |
CPEs | cpe:2.3:a:tribulant:newsletters:*:*:*:*:*:wordpress:*:* |
Fri, 06 Sep 2024 14:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Tribulant
Tribulant newsletters |
|
CPEs | cpe:2.3:a:tribulant:newsletters:*:*:*:*:*:*:*:* | |
Vendors & Products |
Tribulant
Tribulant newsletters |
|
Metrics |
ssvc
|
Fri, 06 Sep 2024 03:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | The Newsletters plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including, 4.9.9.2. This is due to the plugin not restricting what user meta can be updated as screen options. This makes it possible for authenticated attackers, with subscriber-level access and above, to escalate their privileges to that of an administrator. Please note that this only affects users with access to edit/update screen options, which means an administrator would need to grant lower privilege users with access to the Sent & Draft Emails page of the plugin in order for this to be exploited. | |
Title | Newsletters <= 4.9.9.2 - Authenticated Privilege Escalation | |
Weaknesses | CWE-269 | |
References |
|
|
Metrics |
cvssV3_1
|
MITRE
Status: PUBLISHED
Assigner: Wordfence
Published: 2024-09-06T03:30:40.728Z
Updated: 2024-09-06T13:37:42.412Z
Reserved: 2024-08-27T22:39:07.593Z
Link: CVE-2024-8247
Vulnrichment
Updated: 2024-09-06T13:36:53.025Z
NVD
Status : Analyzed
Published: 2024-09-06T04:15:05.573
Modified: 2024-09-26T21:49:54.290
Link: CVE-2024-8247
Redhat
No data.