CVE-2024-8430

CVSS 3.1 Score 5.3 of 10 (medium)

Details

Published Oct 1, 2024
Updated: Oct 4, 2024
CWE ID 862

Summary

CVE-2024-8430 is a vulnerability affecting the Spice Starter Sites plugin for WordPress. The issue lies in the plugin's function, spice_starter_sites_importer_creater, which lacks proper capability checks. As a result, unauthenticated attackers are able to bypass security measures and import demo content, leading to unauthorized modification of data on impacted sites. This vulnerability poses a risk to WordPress installations using the Spice Starter Sites plugin in versions 1.2.5 and below.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share