PT-2024-16088 · WordPress · Wp Project Manager
Matthew Rollings
+1
·
Published
2024-11-13
·
Updated
2025-02-05
·
CVE-2024-10174
CVSS v3.1
7.3
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L |
Name of the Vulnerable Software and Affected Versions
The WP Project Manager versions up to, and including, 2.6.13
Description
The issue is related to Insecure Direct Object Reference, which affects the plugin due to missing validation on the
user id user-controlled key in the Abstract Permission class. This allows unauthenticated attackers to spoof their identity as an administrator and access all of the plugin's REST routes.Recommendations
For versions up to, and including, 2.6.13, update the plugin to a version later than 2.6.13 to mitigate the risk. As a temporary workaround, consider restricting access to the plugin's REST routes until a patch is available. Avoid using the
user id key in the affected API endpoints until the issue is resolved.Fix
IDOR
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Wp Project Manager