Unauthenticated Attackers Can Log in as Any Existing User on the Site
CVE-2024-5432
What is CVE-2024-5432?
The Lifeline Donation plugin for WordPress is susceptible to an authentication bypass issue due to inadequate user verification during the checkout process. This vulnerability allows unauthenticated attackers to gain access as any existing user on the WordPress site, including users with administrative privileges, provided they know the email associated with the account. It highlights a significant security risk as it can lead to unauthorized actions on the site, potentially compromising sensitive user data and overall site integrity.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
Lifeline Donation * <= 1.2.6
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved