CVE-2024-8349
Last modified
CVE-2024-8349 is a high-severity vulnerability rated 7.2/10 on the CVSS scale. The Uncanny Groups for LearnDash plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including, 6.1.0.1. This is due to the plugin not properly restricting what users a group leader can edit. EPSS estimates a 1.13% chance of exploitation in the next 30 days.
Description
The Uncanny Groups for LearnDash plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including, 6.1.0.1. This is due to the plugin not properly restricting what users a group leader can edit. This makes it possible for authenticated attackers, with group leader-level access and above, to change admin account email addresses which can subsequently lead to admin account access.
Metrics
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Uncannyowl | Uncanny Groups For Learndash | < 6.1.1 |
References
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2024-8349?
How severe is CVE-2024-8349?
How do I fix CVE-2024-8349?
Are you affected by CVE-2024-8349?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
