The Frontend Post Submission Manager Lite – Frontend Posting WordPress Plugin plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the save_global_settings and process_form_edit functions in all versions up to, and including, 1.2.2. This makes it possible for authenticated attackers, with Subscriber-level access and above, to update the plugin's settings and forms.
References
Configurations
Configuration 1 (hide)
|
History
11 Sep 2024, 17:41
Type | Values Removed | Values Added |
---|---|---|
References | () https://plugins.trac.wordpress.org/browser/frontend-post-submission-manager-lite/tags/1.2.2/includes/classes/admin/class-fpsml-ajax-admin.php#L25 - Product | |
References | () https://plugins.trac.wordpress.org/changeset/3147218/frontend-post-submission-manager-lite/trunk/includes/classes/admin/class-fpsml-ajax-admin.php - Patch | |
References | () https://www.wordfence.com/threat-intel/vulnerabilities/id/e84b68b6-1ce8-45fb-823f-a61158aa4d21?source=cve - Third Party Advisory | |
CPE | cpe:2.3:a:wpshuffle:frontend_post_submission_manager:*:*:*:*:lite:wordpress:*:* | |
First Time |
Wpshuffle frontend Post Submission Manager
Wpshuffle |
06 Sep 2024, 12:08
Type | Values Removed | Values Added |
---|---|---|
Summary |
|
06 Sep 2024, 07:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2024-09-06 07:15
Updated : 2024-09-11 17:41
NVD link : CVE-2024-8427
Mitre link : CVE-2024-8427
CVE.ORG link : CVE-2024-8427
JSON object : View
Products Affected
wpshuffle
- frontend_post_submission_manager
CWE
CWE-862
Missing Authorization