CVE-2024-8350

CVSS 3.1 Score 2.7 of 10 (low)

Details

Published Sep 25, 2024
Updated: Oct 2, 2024
CWE ID 862

Summary

CVE-2024-8350 is a vulnerability affecting the Uncanny Groups for LearnDash plugin for WordPress. This issue stems from a missing capability check on the /wp-json/ulgm_management/v1/add_user/ REST API endpoint, which exists in all versions up to and including 6.1.0.1. As a result, authenticated attackers with group leader-level access or higher can successfully add users to their group, granting them the ability to exploit CVE-2024-8349 and ultimately obtain admin access to the WordPress site.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share