WCFM Vulnerability Allows Attackers to Change Admin Email Addresses and Reset Passwords
CVE-2024-8290
8.8HIGH
Key Information
- Vendor
- WCFM
- Status
- Frontend Manager For WooCommerce Along With Bookings Subscription Listings Compatible
- Vendor
- CVE Published:
- 25 September 2024
Summary
The WCFM – Frontend Manager for WooCommerce along with Bookings Subscription Listings Compatible plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 6.7.12 via the WCFM_Customers_Manage_Controller::processing function due to missing validation on the ID user controlled key. This makes it possible for authenticated attackers, with subscriber/customer-level access and above, to change the email address of administrator user accounts which allows them to reset the password and access the administrator account.
CVSS V3.1
Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published.
Collectors
NVD Database