Unauthenticated Attackers Can Access and Update User Accounts
CVE-2024-8791

9.8CRITICAL

Summary

A vulnerability exists in the Charitable – Donations Plugin & Fundraising Platform for WordPress that allows for privilege escalation across all versions up to and including 1.8.1.14. This security flaw stems from the plugin's inadequate verification of a user's identity when the ID parameter is provided through the update_core_user() function. As a result, attackers lacking authentication can manipulate user accounts, potentially changing email addresses and passwords for any user, including those with administrator privileges. This exposure can lead to significant unauthorized access and control over user accounts, emphasizing the need for prompt remediation.

Affected Version(s)

Charitable – Donation Plugin for WordPress – Fundraising with Recurring Donations & More * <= 1.8.1.14

References

CVSS V3.1

Score:
9.8
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

wesley
.