PT-2024-38870 · WordPress · Reviews Feed – Add Testimonials/Customer Reviews From Google Reviews

Jack_Sparrow

+1

·

Published

2024-08-27

·

Updated

2024-08-30

·

CVE-2024-8199

CVSS v3.1

4.3

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions: Reviews Feed – Add Testimonials and Customer Reviews From Google Reviews, Yelp, TripAdvisor, and More plugin for WordPress versions 1.1.2 and earlier
Description: The issue is related to a missing capability check on the update api key function, allowing authenticated attackers with Subscriber-level access and above to update API Key options. This makes it possible for attackers to modify data without proper authorization.
Recommendations: For versions 1.1.2 and earlier, update the plugin immediately to patch the flaw. As a temporary workaround, consider restricting access to the update api key function until a patch is available.

Fix

Missing Authorization

Weakness Enumeration

Related Identifiers

CVE-2024-8199

Affected Products

Reviews Feed – Add Testimonials/Customer Reviews From Google Reviews