Unauthorized Data Modification in Passwords Manager Plugin for WordPress
CVE-2024-12614
4.3MEDIUM
What is CVE-2024-12614?
The Passwords Manager plugin for WordPress contains a vulnerability that allows authenticated attackers, with Subscriber-level access or higher, to manipulate plugin settings due to a lack of proper capability checks on specific AJAX actions. This flaw affects all versions up to and including 1.4.8, enabling unauthorized users to update settings and manage passwords without appropriate permissions, leading to potential data integrity issues.
Affected Version(s)
Passwords Manager * <= 1.4.8