CVE-2024-10311

The External Database Based Actions plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 0.1. This is due to a missing capability check in the 'edba_admin_handle' function. This makes it possible for authenticated attackers, with subscriber-level permissions and above, to update the plugin settings and log in as any existing user on the site, such as an administrator.
Configurations

Configuration 1 (hide)

cpe:2.3:a:cmorillas1:external_database_based_actions:0.1:*:*:*:*:wordpress:*:*

History

No history.

Information

Published : 2024-11-15 10:15

Updated : 2024-11-19 17:03


NVD link : CVE-2024-10311

Mitre link : CVE-2024-10311

CVE.ORG link : CVE-2024-10311


JSON object : View

Products Affected

cmorillas1

  • external_database_based_actions
CWE
CWE-288

Authentication Bypass Using an Alternate Path or Channel