PT-2024-26377 · WordPress · Country State City Dropdown Cf7

Lucio Sá

·

Published

2024-05-02

·

Updated

2024-05-11

·

CVE-2024-3520

CVSS v3.1

4.3

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions The Country State City Dropdown CF7 plugin for WordPress versions up to, and including, 2.7.1
Description The issue allows authenticated attackers with subscriber access and above to modify data without proper authorization. This is due to a missing capability check on the tc csca patch settings function. As a result, attackers can add states or cities to the dropdown.
Recommendations For versions up to, and including, 2.7.1, update to a version higher than 2.7.1 to resolve the issue. As a temporary workaround, consider restricting access to the tc csca patch settings function until a patch is available.

Fix

Missing Authorization

Weakness Enumeration

Related Identifiers

CVE-2024-3520

Affected Products

Country State City Dropdown Cf7