The Uncanny Groups for LearnDash plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including, 6.1.0.1. This is due to the plugin not properly restricting what users a group leader can edit. This makes it possible for authenticated attackers, with group leader-level access and above, to change admin account email addresses which can subsequently lead to admin account access.
Metrics
Affected Vendors & Products
References
History
Wed, 02 Oct 2024 17:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
CPEs | cpe:2.3:a:uncannyowl:uncanny_groups_for_learndash:*:*:*:*:*:wordpress:*:* |
Wed, 25 Sep 2024 14:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Uncannyowl
Uncannyowl uncanny Groups For Learndash |
|
CPEs | cpe:2.3:a:uncannyowl:uncanny_groups_for_learndash:*:*:*:*:*:*:*:* | |
Vendors & Products |
Uncannyowl
Uncannyowl uncanny Groups For Learndash |
|
Metrics |
ssvc
|
Wed, 25 Sep 2024 03:00:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | The Uncanny Groups for LearnDash plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including, 6.1.0.1. This is due to the plugin not properly restricting what users a group leader can edit. This makes it possible for authenticated attackers, with group leader-level access and above, to change admin account email addresses which can subsequently lead to admin account access. | |
Title | Uncanny Groups for LearnDash <= 6.1.0.1 - Authenticated (Group Leader+) Privilege Escalation | |
Weaknesses | CWE-862 | |
References |
| |
Metrics |
cvssV3_1
|
MITRE
Status: PUBLISHED
Assigner: Wordfence
Published: 2024-09-25T02:32:25.610Z
Updated: 2024-09-25T13:36:24.147Z
Reserved: 2024-08-30T14:21:49.520Z
Link: CVE-2024-8349
Vulnrichment
Updated: 2024-09-25T13:36:13.114Z
NVD
Status : Analyzed
Published: 2024-09-25T03:15:03.817
Modified: 2024-10-02T16:50:09.673
Link: CVE-2024-8349
Redhat
No data.