CVE-2019-6703
Last modified
CVE-2019-6703 is a vulnerability of currently unknown severity. Incorrect access control in migla_ajax_functions.php in the Calmar Webmedia Total Donations plugin through 2.0.5 for WordPress allows unauthenticated attackers to update arbitrary WordPress option values, leading to site takeover. These attackers can send requests to wp-admin/admin-ajax.php to call the miglaA_update_me action to change arbitrary options on affected sites. EPSS estimates a 26.08% chance of exploitation in the next 30 days.
Description
Incorrect access control in migla_ajax_functions.php in the Calmar Webmedia Total Donations plugin through 2.0.5 for WordPress allows unauthenticated attackers to update arbitrary WordPress option values, leading to site takeover. These attackers can send requests to wp-admin/admin-ajax.php to call the miglaA_update_me action to change arbitrary options on affected sites. This can be used to enable new user registration and set the default role for new users to Administrator.
Metrics
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Calmar-Webmedia | Total Donations | <= 2.0.5 |
References
- https://wpvulndb.com/vulnerabilities/9208Third Party Advisory
- https://wpvulndb.com/vulnerabilities/9208Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2019-6703?
How severe is CVE-2019-6703?
How do I fix CVE-2019-6703?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2019
- CVE-2019-6696An improper input validation vulnerability in FortiOS 6.2.1,…6.1
- CVE-2019-6697An Improper Neutralization of Input vulnerability affecting …6.1
- CVE-2019-6698Use of Hard-coded Credentials vulnerability in FortiRecorder…9.8
- CVE-2019-6699An improper neutralization of input vulnerability in Fortine…5.4
- CVE-2019-6700An information exposure vulnerability in the external authen…6.5
- CVE-2019-6702The MasterCard Qkr! app before 5.0.8 for iOS has Missing SSL…
- CVE-2019-6706Lua 5.3.5 has a use-after-free in lua_upvaluejoin in lapi.c.…7.5
- CVE-2019-6707PHPSHE 1.7 has SQL injection via the admin.php?mod=product&a…
- CVE-2019-6708PHPSHE 1.7 has SQL injection via the admin.php?mod=order sta…
- CVE-2019-6710Zyxel NBG-418N v2 v1.00(AAXM.4)C0 devices allow login.cgi CS…
- CVE-2019-6713app\admin\controller\RouteController.php in ThinkCMF 5.0.190…
- CVE-2019-6714An issue was discovered in BlogEngine.NET through 3.3.6.0. A…
Are you affected by CVE-2019-6703?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
