CVE-2024-10717
Last modified
CVE-2024-10717 is a medium-severity vulnerability rated 6.5/10 on the CVSS scale. The Styler for Ninja Forms plugin for WordPress is vulnerable to unauthorized modification of data that can lead to a denial of service due to a missing capability check on the deactivate_license function in all versions up to, and including, 3.3.4. This makes it possible for authenticated attackers, with Subscriber-level access and above, to delete arbitrary option values on the WordPress site. EPSS estimates a 0.40% chance of exploitation in the next 30 days.
Description
The Styler for Ninja Forms plugin for WordPress is vulnerable to unauthorized modification of data that can lead to a denial of service due to a missing capability check on the deactivate_license function in all versions up to, and including, 3.3.4. This makes it possible for authenticated attackers, with Subscriber-level access and above, to delete arbitrary option values on the WordPress site. This can be leveraged to delete an option that would create an error on the site and deny service to legitimate users. Note: This issue can also be used to add arbitrary options with an empty value.
Metrics
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Wpmonks | Styler For Ninja Forms | <= 3.3.4 |
References
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2024-10717?
How severe is CVE-2024-10717?
How do I fix CVE-2024-10717?
How Strix Helps
- Uncovering a hidden BOLA in Appsmith's snapshot logicStrix autonomously discovered a BOLA/IDOR vulnerability in Appsmith's snapshot deletion path.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2024
- CVE-2024-10710The YaDisk Files WordPress plugin through 1.2.5 does not san…3.5
- CVE-2024-10711The WooCommerce Report plugin for WordPress is vulnerable to…8.8
- CVE-2024-10713A vulnerability in szad670401/hyperlpr v3.0 allows for a Den…7.5
- CVE-2024-10714A vulnerability in binary-husky/gpt_academic version 3.83 al…7.5
- CVE-2024-10715The MapPress Maps for WordPress plugin for WordPress is vuln…5.4
- CVE-2024-10716Pega Platform versions 8.1 to Infinity 24.2.0 are affected b…4.8
- CVE-2024-10718In phpipam/phpipam version 1.5.1, the Secure attribute for s…7.5
- CVE-2024-10719A stored cross-site scripting (XSS) vulnerability exists in …5.4
- CVE-2024-1072The Website Builder by SeedProd — Theme Builder, Landing Pag…7.5
- CVE-2024-10720A stored cross-site scripting (XSS) vulnerability exists in …6.1
- CVE-2024-10721A stored cross-site scripting (XSS) vulnerability was discov…5.4
- CVE-2024-10722A stored cross-site scripting (XSS) vulnerability exists in …5.4
Are you affected by CVE-2024-10717?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
