Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2024-8292

Опубликовано: 06 сент. 2024
Источник: nvd
CVSS3: 9.8
EPSS Низкий

Описание

The WP-Recall – Registration, Profile, Commerce & More plugin for WordPress is vulnerable to privilege escalation/account takeover in all versions up to, and including, 16.26.8. This is due to to plugin not properly verifying a user's identity during new order creation. This makes it possible for unauthenticated attackers to supply any email through the user_email field and update the password for that user during new order creation. This requires the commerce addon to be enabled in order to exploit.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:plechevandrey:wp-recall:*:*:*:*:*:wordpress:*:*
Версия до 16.26.9 (исключая)

EPSS

Процентиль: 74%
0.0085
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-639

Связанные уязвимости

CVSS3: 9.8
github
больше 1 года назад

The WP-Recall – Registration, Profile, Commerce & More plugin for WordPress is vulnerable to privilege escalation/account takeover in all versions up to, and including, 16.26.8. This is due to to plugin not properly verifying a user's identity during new order creation. This makes it possible for unauthenticated attackers to supply any email through the user_email field and update the password for that user during new order creation. This requires the commerce addon to be enabled in order to exploit.

EPSS

Процентиль: 74%
0.0085
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-639