CVE-2024-8290
CVSS 3.1 Score 8.8 of 10 (high)
Details
Summary
CVE-2024-8290 is a vulnerability affecting the WCFM – Frontend Manager for WooCommerce and Bookings Subscription Listings Compatible plugins for WordPress. This issue, present in all versions up to 6.7.12, enables authenticated attackers with subscriber or customer-level access to manipulate user IDs. This allows them to modify the email address of administrator accounts, ultimately granting access to reset passwords and assume administrator privileges. The vulnerability arises due to the absence of validation checks on user-controlled keys, making it essential for users to upgrade to the latest plugin versions as soon as possible to mitigate this risk.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.