CVE-2024-8349

CVSS 3.1 Score 7.2 of 10 (high)

Details

Published Sep 25, 2024
Updated: Oct 2, 2024
CWE ID 862

Summary

CVE-2024-8349 is a privilege escalation vulnerability affecting the Uncanny Groups for LearnDash plugin for WordPress. Versions up to and including 6.1.0.1 are susceptible to this issue. An attacker with group leader-level access or higher can exploit this vulnerability to modify admin account email addresses. While this action doesn't grant direct admin access, it can be used as a stepping stone for attackers to ultimately gain control of admin accounts. This security flaw could pose a significant risk to WordPress websites using the Uncanny Groups plugin.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share