CVE-2024-8290

CVSS 3.1 Score 8.8 of 10 (high)

Details

Published Sep 25, 2024
Updated: Oct 2, 2024
CWE ID 639

Summary

CVE-2024-8290 is a vulnerability affecting the WCFM – Frontend Manager for WooCommerce and Bookings Subscription Listings Compatible plugins for WordPress. This issue, present in all versions up to 6.7.12, enables authenticated attackers with subscriber or customer-level access to manipulate user IDs. This allows them to modify the email address of administrator accounts, ultimately granting access to reset passwords and assume administrator privileges. The vulnerability arises due to the absence of validation checks on user-controlled keys, making it essential for users to upgrade to the latest plugin versions as soon as possible to mitigate this risk.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share