The Donation Forms by Charitable – Donations Plugin & Fundraising Platform for WordPress plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including, 1.8.1.14. This is due to the plugin not properly verifying a user's identity when the ID parameter is supplied through the update_core_user() function. This makes it possible for unauthenticated attackers to update the email address and password of arbitrary user accounts, including administrators, which can then be used to log in to those user accounts.
Metrics
Affected Vendors & Products
References
History
Tue, 24 Sep 2024 14:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Wpcharitable
Wpcharitable charitable |
|
CPEs | cpe:2.3:a:wpcharitable:charitable:*:*:*:*:*:wordpress:*:* | |
Vendors & Products |
Wpcharitable
Wpcharitable charitable |
|
Metrics |
ssvc
|
Tue, 24 Sep 2024 02:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | The Donation Forms by Charitable – Donations Plugin & Fundraising Platform for WordPress plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including, 1.8.1.14. This is due to the plugin not properly verifying a user's identity when the ID parameter is supplied through the update_core_user() function. This makes it possible for unauthenticated attackers to update the email address and password of arbitrary user accounts, including administrators, which can then be used to log in to those user accounts. | |
Title | Donation Forms by Charitable – Donations Plugin & Fundraising Platform for WordPress <= 1.8.1.14 - Insecure Direct Object Reference to Account Takeover and Privilege Escalation | |
Weaknesses | CWE-639 | |
References |
|
|
Metrics |
cvssV3_1
|
MITRE
Status: PUBLISHED
Assigner: Wordfence
Published: 2024-09-24T02:31:00.740Z
Updated: 2024-09-24T13:46:18.285Z
Reserved: 2024-09-13T16:21:29.906Z
Link: CVE-2024-8791
Vulnrichment
Updated: 2024-09-24T13:46:12.487Z
NVD
Status : Analyzed
Published: 2024-09-24T03:15:03.547
Modified: 2024-09-26T16:25:34.120
Link: CVE-2024-8791
Redhat
No data.