The Bridge Core plugin for WordPress is vulnerable to unauthorized modification of data or loss of data due to a missing capability check on the 'import_action' and 'install_plugin_per_demo' functions in versions up to, and including, 3.3. This makes it possible for authenticated attackers with subscriber-level permissions or above, to delete or change plugin settings, import demo data, and install limited plugins.
Metrics
Affected Vendors & Products
References
History
Tue, 15 Oct 2024 18:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Qode
Qode bridge Core |
|
CPEs | cpe:2.3:a:qode:bridge_core:*:*:*:*:*:*:*:* | |
Vendors & Products |
Qode
Qode bridge Core |
|
Metrics |
ssvc
|
Sat, 12 Oct 2024 02:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | The Bridge Core plugin for WordPress is vulnerable to unauthorized modification of data or loss of data due to a missing capability check on the 'import_action' and 'install_plugin_per_demo' functions in versions up to, and including, 3.3. This makes it possible for authenticated attackers with subscriber-level permissions or above, to delete or change plugin settings, import demo data, and install limited plugins. | |
Title | Bridge Core <= 3.3 - Missing Authorization to Authenticated (Subscriber+) Demo Import | |
Weaknesses | CWE-862 | |
References |
| |
Metrics |
cvssV3_1
|
MITRE
Status: PUBLISHED
Assigner: Wordfence
Published: 2024-10-12T02:05:43.175Z
Updated: 2024-10-15T17:40:18.621Z
Reserved: 2024-10-11T12:45:07.126Z
Link: CVE-2024-9860
Vulnrichment
Updated: 2024-10-15T17:39:44.875Z
NVD
Status : Awaiting Analysis
Published: 2024-10-12T03:15:02.757
Modified: 2024-10-15T12:57:46.880
Link: CVE-2024-9860
Redhat
No data.