PT-2024-38917 · WordPress · Multivendorx
Wesley
·
Published
2024-09-04
·
Updated
2024-09-07
·
CVE-2024-8289
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions:
MultiVendorX – The Ultimate WooCommerce Multivendor Marketplace Solution plugin for WordPress versions prior to 4.2.1
Description:
The issue is related to an insufficient capability check on the
update item permissions check and create item permissions check functions. This allows unauthenticated attackers to change the password of any user with the vendor role, create new users with the vendor role, and demote other users like administrators to the vendor role.Recommendations:
For versions prior to 4.2.1, update to version 4.2.1 to patch this flaw. As a temporary workaround, consider restricting access to the
update item permissions check and create item permissions check functions until a patch is available. Avoid using these functions in the affected API endpoints until the issue is resolved.Fix
Missing Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Multivendorx