The HurryTimer – An Scarcity and Urgency Countdown Timer for WordPress & WooCommerce plugin for WordPress is vulnerable to unauthorized post publication due to a missing capability check on the activateCampaign() function in all versions up to, and including, 2.10.0. This makes it possible for authenticated attackers, with contributor-level access and above, to publish arbitrary posts like ones they have submitted for review, or a site administrator has in draft.
Metrics
Affected Vendors & Products
References
History
Thu, 24 Oct 2024 19:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Thu, 24 Oct 2024 07:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | The HurryTimer – An Scarcity and Urgency Countdown Timer for WordPress & WooCommerce plugin for WordPress is vulnerable to unauthorized post publication due to a missing capability check on the activateCampaign() function in all versions up to, and including, 2.10.0. This makes it possible for authenticated attackers, with contributor-level access and above, to publish arbitrary posts like ones they have submitted for review, or a site administrator has in draft. | |
Title | HurryTimer – An Scarcity and Urgency Countdown Timer for WordPress & WooCommerce <= 2.10.0 - Missing Authorization to Authenticated (Contributor+) Arbitrary Post Publication | |
Weaknesses | CWE-862 | |
References |
| |
Metrics |
cvssV3_1
|
MITRE
Status: PUBLISHED
Assigner: Wordfence
Published: 2024-10-24T07:35:56.502Z
Updated: 2024-10-24T18:40:47.563Z
Reserved: 2024-09-10T17:06:35.815Z
Link: CVE-2024-8667
Vulnrichment
Updated: 2024-10-24T18:40:44.367Z
NVD
Status : Awaiting Analysis
Published: 2024-10-24T08:15:02.430
Modified: 2024-10-25T12:56:07.750
Link: CVE-2024-8667
Redhat
No data.