The Passwords Manager plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'pms_save_setting' and 'post_new_pass' AJAX actions in all versions up to, and including, 1.4.8. This makes it possible for authenticated attackers, with Subscriber-level access and above, to update the plugins settings and add passwords.
References
Configurations
History
17 Jan 2025, 22:17
Type | Values Removed | Values Added |
---|---|---|
CPE | cpe:2.3:a:hirewebxperts:passwords_manager:*:*:*:*:*:wordpress:*:* | |
CWE | CWE-862 | |
First Time |
Hirewebxperts passwords Manager
Hirewebxperts |
|
References | () https://plugins.trac.wordpress.org/changeset/3221505/passwords-manager/trunk/include/pms-passwords-ajax-action.php - Patch | |
References | () https://plugins.trac.wordpress.org/changeset/3221505/passwords-manager/trunk/include/pms-settings-ajax-action.php - Patch | |
References | () https://www.wordfence.com/threat-intel/vulnerabilities/id/898c5554-fd02-47a2-a1f9-1c488cfab57e?source=cve - Third Party Advisory | |
Summary |
|
16 Jan 2025, 10:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2025-01-16 10:15
Updated : 2025-01-17 22:17
NVD link : CVE-2024-12614
Mitre link : CVE-2024-12614
CVE.ORG link : CVE-2024-12614
JSON object : View
Products Affected
hirewebxperts
- passwords_manager