CVE-2024-8675
CVSS 3.1 Score 4.3 of 10 (medium)
Details
Published Oct 1, 2024
Updated: Oct 4, 2024
CWE ID 862
Summary
CVE-2024-8675 is a vulnerability affecting the Soumettre.fr plugin for WordPress. The issue lies in the soumettre_disconnect_gateway function, which lacks adequate capability checks in all versions up to 2.1.2. This oversight enables authenticated attackers, even those with low-level Subscriber access, to manipulate the plugin by disconnecting the gateway and deleting the API key, potentially leading to unauthorized data modifications.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.