CVE-2024-4410
Last modified
CVE-2024-4410 is a medium-severity vulnerability rated 5.4/10 on the CVSS scale. The IgnitionDeck Crowdfunding Platform plugin for WordPress is vulnerable to Missing Authorization in versions up to, and including, 1.9.8. This is due to missing capability checks on various functions called via AJAX actions in the ~/classes/class-idf-wizard.php file. EPSS estimates a 0.38% chance of exploitation in the next 30 days.
Description
The IgnitionDeck Crowdfunding Platform plugin for WordPress is vulnerable to Missing Authorization in versions up to, and including, 1.9.8. This is due to missing capability checks on various functions called via AJAX actions in the ~/classes/class-idf-wizard.php file. This makes it possible for authenticated attackers, with subscriber access or higher, to execute various AJAX actions. This includes actions to change the permalink structure, plugin settings and others.
Metrics
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L
Weakness Enumeration
References
Timeline
- Published
- Last Modified
- Status
- Deferred
Frequently Asked Questions
What is CVE-2024-4410?
How severe is CVE-2024-4410?
How do I fix CVE-2024-4410?
How Strix Helps
- Uncovering a hidden BOLA in Appsmith's snapshot logicStrix autonomously discovered a BOLA/IDOR vulnerability in Appsmith's snapshot deletion path.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2024
- CVE-2024-44094In ppmp_protect_mfcfw_buf of code/drm_fw.c, there is a possi…7.8
- CVE-2024-44095In ppmp_protect_mfcfw_buf of code/drm_fw.c, there is a possi…7.8
- CVE-2024-44096there is a possible arbitrary read due to an insecure defaul…4.4
- CVE-2024-44097According to the researcher: "The TLS connections are encryp…9.8
- CVE-2024-44098In lwis_device_event_states_clear_locked of lwis_event.c, th…7.4
- CVE-2024-44099There is a possible Local bypass of user interaction due to …5.5
- CVE-2024-44100Android before 2024-10-05 on Google Pixel devices allows inf…7.5
- CVE-2024-44101there is a possible Null Pointer Dereference (modem crash) d…7.5
- CVE-2024-44102A vulnerability has been identified in PP TeleControl Server…10
- CVE-2024-44103DLL hijacking in the management console of Ivanti Workspace …7.8
- CVE-2024-44104An incorrectly implemented authentication scheme that is sub…7.8
- CVE-2024-44105Cleartext transmission of sensitive information in the manag…7.8
Are you affected by CVE-2024-4410?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
