CVE-2024-11725

CVSS 3.1 Score 8.8 of 10 (high)

Details

Published Jan 7, 2025
CWE ID 862

Summary

CVE-2024-11725: The SMS Alert Order Notifications plugin for WordPress, specifically versions up to 3.7.6, is found to have a vulnerability. This issue stems from a missing capability check on the updateWcWarrantySettings() function. Authenticated attackers with subscriber-level access or higher can exploit this flaw, leading to unauthorized data modification. The impact includes the ability to update arbitrary options on a WordPress site. Malicious actors may utilize this vulnerability to change the default role for registration to administrator, granting themselves administrative user access, only if the woocommerce-warranty plugin is installed.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share