Unauthenticated Attackers Can Access and Update User Accounts
CVE-2024-8791
Key Information:
- Vendor
- Wordpress
- Vendor
- CVE Published:
- 24 September 2024
Summary
A vulnerability exists in the Charitable – Donations Plugin & Fundraising Platform for WordPress that allows for privilege escalation across all versions up to and including 1.8.1.14. This security flaw stems from the plugin's inadequate verification of a user's identity when the ID parameter is provided through the update_core_user() function. As a result, attackers lacking authentication can manipulate user accounts, potentially changing email addresses and passwords for any user, including those with administrator privileges. This exposure can lead to significant unauthorized access and control over user accounts, emphasizing the need for prompt remediation.
Affected Version(s)
Charitable – Donation Plugin for WordPress – Fundraising with Recurring Donations & More * <= 1.8.1.14
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved