CVE-2024-0829

CVSS 3.1 Score 4.3 of 10 (medium)

Details

Published Mar 13, 2024

Summary

CVE-2024-0829 is a vulnerability found in the Comments Extra Fields For Post, Pages, and CPT plugin for WordPress. This vulnerability affects all versions up to and including 5.0. The issue arises from missing or incorrect capability checks on several ajax actions, which allows authenticated attackers with subscriber access or higher privileges to exploit these actions. As a result, attackers can modify comment form fields and update plugin settings. The risk score for this vulnerability is 5, indicating a medium severity level. No changes have been made to the rating provided by [email protected], which states that the exploitability score is 2.8 out of 10. The base severity score is categorized as medium at 4.3 out of 10. The privileges required for exploitation are low, with no user interaction required, and the attack vector is through the network. The impact on integrity is low, and there is no impact on confidentiality. The attack complexity is low, and there is no availability impact identified. Remediation steps or further analysis are not provided in the information available.

Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share

Prioritize, Pinpoint, and Act to Prevent Vulnerability Exploits with Recorded Future

Note: This is just a basic overview providing quick insights into CVE-2024-0829 information. Gain full access to comprehensive CVE data, third party vulnerabilities, compromised credentials and more with Recorded Future
  • Gain complete coverage of your cyber, third party, and physical attack surface
  • Proactively mitigate threats before they turn into costly attacks
  • Make fast, effective, data-driven decisions