CVE-2024-8350
CVSS 3.1 Score 2.7 of 10 (low)
Details
Published Sep 25, 2024
Updated: Oct 2, 2024
CWE ID 862
Summary
CVE-2024-8350 is a vulnerability affecting the Uncanny Groups for LearnDash plugin for WordPress. This issue stems from a missing capability check on the /wp-json/ulgm_management/v1/add_user/ REST API endpoint, which exists in all versions up to and including 6.1.0.1. As a result, authenticated attackers with group leader-level access or higher can successfully add users to their group, granting them the ability to exploit CVE-2024-8349 and ultimately obtain admin access to the WordPress site.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.