CVE-2024-8658

CVSS 3.1 Score 5.3 of 10 (medium)

Details

Published Sep 25, 2024
Updated: Oct 2, 2024
CWE ID 862

Summary

CVE-2024-8658: The myCred plugin, a popular loyalty points and rewards solution for WordPress and WooCommerce, has been identified with a vulnerability. This issue stems from the lack of capability checks on the mycred_update_database() function, found in all versions up to 2.7.3. As a result, unauthenticated attackers are able to manipulate the database, posing a serious risk for unauthorized data modification and potential upgrades. Impacted sites should be updated to the latest version of myCred to mitigate this vulnerability.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share