PT-2024-35688 · WordPress · Login/Signup Popup

1337_Wannabe

+1

·

Published

2024-06-05

·

Updated

2024-07-24

·

CVE-2024-5324

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Login/Signup Popup ( Inline Form + Woocommerce ) plugin for WordPress versions 2.7.1 through 2.7.2
Description The issue is related to a missing capability check on the import settings function, allowing authenticated attackers with Subscriber-level access and above to modify arbitrary options on affected sites. This can be used to enable new user registration and set the default role for new users to Administrator.
Recommendations For versions 2.7.1 through 2.7.2, update to a version that includes a fix for the missing capability check on the import settings function. As a temporary workaround, consider disabling the import settings function until a patch is available. Restrict access to the plugin's settings to minimize the risk of exploitation. Avoid using the plugin until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Incorrect Authorization

Missing Authorization

Weakness Enumeration

Related Identifiers

CVE-2024-5324

Affected Products

Login/Signup Popup