PT-2024-37805 · WordPress · Fundengine

Thanh Nam Tran

·

Published

2024-08-01

·

Updated

2024-11-23

·

CVE-2024-6698

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions FundEngine plugin for WordPress versions up to, and including, 1.7.0
Description The issue is due to the plugin not properly verifying user meta updated through the update user meta function. This allows authenticated attackers, with subscriber-level access and above, to update their user meta, which can be leveraged to update their capabilities to gain administrator access.
Recommendations For versions up to, and including, 1.7.0, update to a version that includes the fix for this issue to prevent privilege escalation. As a temporary workaround, consider restricting access to the update user meta function until a patch is available.

Fix

Missing Authorization

Weakness Enumeration

Related Identifiers

CVE-2024-6698

Affected Products

Fundengine