CVE-2024-8658
CVSS 3.1 Score 5.3 of 10 (medium)
Details
Published Sep 25, 2024
Updated: Oct 2, 2024
CWE ID 862
Summary
CVE-2024-8658: The myCred plugin, a popular loyalty points and rewards solution for WordPress and WooCommerce, has been identified with a vulnerability. This issue stems from the lack of capability checks on the mycred_update_database() function, found in all versions up to 2.7.3. As a result, unauthenticated attackers are able to manipulate the database, posing a serious risk for unauthorized data modification and potential upgrades. Impacted sites should be updated to the latest version of myCred to mitigate this vulnerability.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.