CVE-2024-1108
CVSS 3.1 Score 6.5 of 10 (medium)
Details
Published Feb 21, 2024
Updated: Feb 22, 2024
Summary
CVE-2024-1108 is a vulnerability affecting the Plugin Groups plugin for WordPress. The issue stems from a missing capability check on the admin_init() function, which exists in all versions up to 2.0.6. This oversight enables unauthenticated attackers to manipulate plugin settings, leading to potential misconfigurations. Furthermore, successful exploitation of this vulnerability can result in a denial of service.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Share