PT-2024-38310 · WordPress · Geo Controller

Lucio Sá

·

Published

2024-09-05

·

Updated

2024-09-06

·

CVE-2024-7380

CVSS v3.1

4.3

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions Geo Controller plugin for WordPress versions up to, and including, 8.6.9
Description The issue arises from missing capability checks on the ajax geolocate menu and ajax geolocate remove menu functions, allowing authenticated attackers with Subscriber-level access and above to create or delete WordPress menus. This affects all versions of the Geo Controller plugin up to, and including, 8.6.9.
Recommendations For versions up to, and including, 8.6.9, consider disabling the ajax geolocate menu and ajax geolocate remove menu functions until a patch is available to prevent unauthorized menu creation and deletion. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Missing Authorization

Weakness Enumeration

Related Identifiers

CVE-2024-7380

Affected Products

Geo Controller