CVE-2024-0780

The Enjoy Social Feed plugin for WordPress website WordPress plugin through 6.2.2 does not have authorisation when resetting its database, allowing any authenticated users, such as subscriber to perform such action
Configurations

Configuration 1 (hide)

cpe:2.3:a:mediabetaprojects:enjoy_social_feed:*:*:*:*:*:wordpress:*:*

History

27 Feb 2025, 03:34

Type Values Removed Values Added
CWE CWE-862
References () https://wpscan.com/vulnerability/be3045b1-72e6-450a-8dd2-4702a9328447/ - () https://wpscan.com/vulnerability/be3045b1-72e6-450a-8dd2-4702a9328447/ - Exploit, Third Party Advisory
CPE cpe:2.3:a:mediabetaprojects:enjoy_social_feed:*:*:*:*:*:wordpress:*:*
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 8.8
First Time Mediabetaprojects enjoy Social Feed
Mediabetaprojects

21 Nov 2024, 08:47

Type Values Removed Values Added
Summary
  • (es) El complemento Enjoy Social Feed plugin for WordPress website de WordPress hasta 6.2.2 no tiene autorización para restablecer su base de datos, lo que permite que cualquier usuario autenticado, como un suscriptor, realice dicha acción.
References () https://wpscan.com/vulnerability/be3045b1-72e6-450a-8dd2-4702a9328447/ - () https://wpscan.com/vulnerability/be3045b1-72e6-450a-8dd2-4702a9328447/ -

18 Mar 2024, 19:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-03-18 19:15

Updated : 2025-03-14 17:15


NVD link : CVE-2024-0780

Mitre link : CVE-2024-0780

CVE.ORG link : CVE-2024-0780


JSON object : View

Products Affected

mediabetaprojects

  • enjoy_social_feed
CWE
CWE-862

Missing Authorization