ZeroHour

CVE-2024-0366

CVSS 3.1
4.3 medium
EPSS
<1%p45
Published
()
Modified
Description

The Starbox – the Author Box for Humans plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 3.4.7 via the action function due to missing validation on a user controlled key. This makes it possible for subscribers to view plugin preferences and potentially other user settings.

Vendors
squirrly
Products
starbox
Ecosystems
WordPress
Weakness
CWE-284, CWE-639
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N

In the news

No ingested article mentions this CVE yet.