PT-2024-37743 · WordPress · The Ultimate Wordpress Auction Plugin

Lucio Sá

·

Published

2024-07-27

·

Updated

2024-07-29

·

CVE-2024-6591

CVSS v3.1

5.8

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:C/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions The Ultimate WordPress Auction Plugin versions prior to 4.2.7
Description The issue allows unauthorized email creation and sending due to a missing capability check on the send auction email callback and resend auction email callback functions. This enables unauthenticated attackers to craft emails that include links and send them to any email address.
Recommendations For versions up to and including 4.2.6, update to version 4.2.7 or later to resolve the issue. As a temporary workaround, consider disabling the send auction email callback and resend auction email callback functions until a patch is available. Restrict access to these functions to minimize the risk of exploitation.

Fix

Missing Authorization

Weakness Enumeration

Related Identifiers

CVE-2024-6591

Affected Products

The Ultimate Wordpress Auction Plugin