ZeroHour

CVE-2024-10124

moderate

Unauthenticated Plugin Install/Activation Flaw in Vayu Blocks WordPress Plugin

CVSS 3.1
9.8 critical
EPSS
31%p98
Published
()
Modified
AI analysis

Vayu Blocks – Gutenberg Blocks for WordPress & WooCommerce, a WordPress plugin, is vulnerable to a missing capability check (CWE-284) on its tp_install() function, which can be reached without authentication. An unauthenticated attacker can invoke that function to install and activate arbitrary plugins on the target site. Because arbitrary plugins can be activated, the attacker can chain the flaw with any other installed plugin that has a known remote code execution bug to run code on the server, which is why the flaw carries a critical 9.8 CVSS score. All versions up to and including 1.1.1 are affected, and 1.1.1 contains only a partial fix, so sites on 1.1.1 or earlier remain exposed. No public proof-of-concept or confirmed in-the-wild exploitation is documented, but the flaw carries an elevated 31.2% EPSS (98th percentile), indicating a high likelihood of exploitation within 30 days.

What to do: Update Vayu Blocks to the latest available release beyond 1.1.1, since 1.1.1 is only a partial fix and earlier versions are fully unpatched. Until updated, review the site for unexpectedly installed or activated plugins and ensure no other installed plugin carries a known RCE vulnerability that could be chained into full remote code execution. As no workaround is described in the data, consider temporarily deactivating the plugin on high-value WooCommerce sites if prompt patching is not possible.

Affected
WPVayu Vayu Blocks – Gutenberg Blocks for WordPress & WooCommerce (WordPress plugin)<= 1.1.1 (all versions through 1.1.1; 1.1.1 is only partially patched)
Estimated exposure
moderate≈10,000 active WordPress sites (order of magnitude) — Estimated from the plugin's wordpress.org active-install footprint for this relatively new, niche Gutenberg-blocks plugin (order of 10,000 installs); the source data contains no exact install count, so this is an order-of-magnitude…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

The Vayu Blocks – Gutenberg Blocks for WordPress & WooCommerce plugin for WordPress is vulnerable to unauthorized arbitrary plugin installation and activation due to a missing capability check on the tp_install() function in all versions up to, and including, 1.1.1. This makes it possible for unauthenticated attackers to install and activate arbitrary plugins which can be leveraged to achieve remote code execution if another vulnerable plugin is installed and activated. This vulnerability was partially patched in version 1.1.1.

Ecosystems
WordPress, E-commerce
Weakness
CWE-284
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.