PT-2024-17409 · WordPress · Friends

Colin Xu

·

Published

2024-12-06

·

Updated

2025-01-20

·

CVE-2024-12028

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions The Friends plugin for WordPress versions up to, and including, 3.2.1
Description The issue is related to unauthorized access due to a missing capability check on several REST API endpoints. This allows unauthenticated attackers to send arbitrary friend requests on behalf of another website, accept the friend request for the targeted website, and then communicate with the site as an accepted friend.
Recommendations For versions up to, and including, 3.2.1, update to a version that includes a capability check on the REST API endpoints to prevent unauthorized access. As a temporary workaround, consider restricting access to the REST API endpoints until a patch is available.

Fix

Missing Authorization

Weakness Enumeration

Related Identifiers

BIT-WORDPRESS-2024-12028
BIT-WORDPRESS-MULTISITE-2024-12028
CVE-2024-12028

Affected Products

Friends