The WCFM – Frontend Manager for WooCommerce along with Bookings Subscription Listings Compatible plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 6.7.12 via the WCFM_Customers_Manage_Controller::processing function due to missing validation on the ID user controlled key. This makes it possible for authenticated attackers, with subscriber/customer-level access and above, to change the email address of administrator user accounts which allows them to reset the password and access the administrator account.
Metrics
Affected Vendors & Products
References
History
Wed, 02 Oct 2024 18:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
CPEs | cpe:2.3:a:wclovers:frontend_manager_for_woocommerce_along_with_bookings_subscription_listings_compatible:*:*:*:*:*:wordpress:*:* |
Wed, 25 Sep 2024 14:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Wclovers
Wclovers frontend Manager For Woocommerce Along With Bookings Subscription Listings Compatible |
|
CPEs | cpe:2.3:a:wclovers:frontend_manager_for_woocommerce_along_with_bookings_subscription_listings_compatible:*:*:*:*:*:*:*:* | |
Vendors & Products |
Wclovers
Wclovers frontend Manager For Woocommerce Along With Bookings Subscription Listings Compatible |
|
Metrics |
ssvc
|
Wed, 25 Sep 2024 07:00:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | The WCFM – Frontend Manager for WooCommerce along with Bookings Subscription Listings Compatible plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 6.7.12 via the WCFM_Customers_Manage_Controller::processing function due to missing validation on the ID user controlled key. This makes it possible for authenticated attackers, with subscriber/customer-level access and above, to change the email address of administrator user accounts which allows them to reset the password and access the administrator account. | |
Title | WCFM – Frontend Manager for WooCommerce along with Bookings Subscription Listings Compatible <= 6.7.12 - Insecure Direct Object Reference to Account Takeover/Privilege Escalation | |
Weaknesses | CWE-639 | |
References |
|
|
Metrics |
cvssV3_1
|
MITRE
Status: PUBLISHED
Assigner: Wordfence
Published: 2024-09-25T06:49:01.430Z
Updated: 2024-09-25T13:21:08.505Z
Reserved: 2024-08-28T20:42:11.811Z
Link: CVE-2024-8290
Vulnrichment
Updated: 2024-09-25T13:21:02.391Z
NVD
Status : Analyzed
Published: 2024-09-25T07:15:03.663
Modified: 2024-10-02T18:23:25.890
Link: CVE-2024-8290
Redhat
No data.