The External Database Based Actions plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 0.1. This is due to a missing capability check in the 'edba_admin_handle' function. This makes it possible for authenticated attackers, with subscriber-level permissions and above, to update the plugin settings and log in as any existing user on the site, such as an administrator.
References
Configurations
Configuration 1 (hide)
|
History
No history.
Information
Published : 2024-11-15 10:15
Updated : 2024-11-19 17:03
NVD link : CVE-2024-10311
Mitre link : CVE-2024-10311
CVE.ORG link : CVE-2024-10311
JSON object : View
Products Affected
cmorillas1
- external_database_based_actions
CWE
CWE-288
Authentication Bypass Using an Alternate Path or Channel