The Donation Forms by Charitable – Donations Plugin & Fundraising Platform for WordPress plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including, 1.8.1.14. This is due to the plugin not properly verifying a user's identity when the ID parameter is supplied through the update_core_user() function. This makes it possible for unauthenticated attackers to update the email address and password of arbitrary user accounts, including administrators, which can then be used to log in to those user accounts.
History

Tue, 24 Sep 2024 14:30:00 +0000

Type Values Removed Values Added
First Time appeared Wpcharitable
Wpcharitable charitable
CPEs cpe:2.3:a:wpcharitable:charitable:*:*:*:*:*:wordpress:*:*
Vendors & Products Wpcharitable
Wpcharitable charitable
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 24 Sep 2024 02:45:00 +0000

Type Values Removed Values Added
Description The Donation Forms by Charitable – Donations Plugin & Fundraising Platform for WordPress plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including, 1.8.1.14. This is due to the plugin not properly verifying a user's identity when the ID parameter is supplied through the update_core_user() function. This makes it possible for unauthenticated attackers to update the email address and password of arbitrary user accounts, including administrators, which can then be used to log in to those user accounts.
Title Donation Forms by Charitable – Donations Plugin & Fundraising Platform for WordPress <= 1.8.1.14 - Insecure Direct Object Reference to Account Takeover and Privilege Escalation
Weaknesses CWE-639
References
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: Wordfence

Published: 2024-09-24T02:31:00.740Z

Updated: 2024-09-24T13:46:18.285Z

Reserved: 2024-09-13T16:21:29.906Z

Link: CVE-2024-8791

cve-icon Vulnrichment

Updated: 2024-09-24T13:46:12.487Z

cve-icon NVD

Status : Analyzed

Published: 2024-09-24T03:15:03.547

Modified: 2024-09-26T16:25:34.120

Link: CVE-2024-8791

cve-icon Redhat

No data.