PT-2024-15968 · WordPress · Rover Idx Plugin

István Márton

·

Published

2024-10-22

·

Updated

2024-10-25

·

CVE-2024-10003

CVSS v3.1

6.3

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
Name of the Vulnerable Software and Affected Versions Rover IDX plugin for WordPress versions up to, and including, 3.0.0.2903
Description The issue allows unauthorized access, modification, and loss of data due to a missing capability check on multiple functions. This makes it possible for authenticated attackers, with subscriber-level access and above, to add, modify, or delete plugin options.
Recommendations For versions up to, and including, 3.0.0.2903, update to a version that includes a capability check on all functions to prevent unauthorized access. As a temporary workaround, consider restricting access to the plugin options to minimize the risk of exploitation.

Fix

Missing Authorization

Weakness Enumeration

Related Identifiers

CVE-2024-10003

Affected Products

Rover Idx Plugin