PT-2024-16088 · WordPress · Wp Project Manager

Matthew Rollings

+1

·

Published

2024-11-13

·

Updated

2025-02-05

·

CVE-2024-10174

CVSS v3.1

7.3

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
Name of the Vulnerable Software and Affected Versions The WP Project Manager versions up to, and including, 2.6.13
Description The issue is related to Insecure Direct Object Reference, which affects the plugin due to missing validation on the user id user-controlled key in the Abstract Permission class. This allows unauthenticated attackers to spoof their identity as an administrator and access all of the plugin's REST routes.
Recommendations For versions up to, and including, 2.6.13, update the plugin to a version later than 2.6.13 to mitigate the risk. As a temporary workaround, consider restricting access to the plugin's REST routes until a patch is available. Avoid using the user id key in the affected API endpoints until the issue is resolved.

Fix

IDOR

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2024-10174

Affected Products

Wp Project Manager