ZeroHour

CVE-2024-5324

CVSS 3.1
8.8 high
EPSS
2%p73
Published
()
Modified
Description

Multiple plugins for WordPress utilizing the XootiX Framework are vulnerable to unauthorized modification of data due to a missing capability check on the 'import_settings' function in various versions. This makes it possible for authenticated attackers, with Subscriber-level access and above, to change arbitrary options on affected sites. This can be used to enable new user registration and set the default role for new users to Administrator.

Vendors
xootix
Products
login\/signup popup, otp login woocommerce \& gravity forms, side cart woocommerce, waitlist woocommerce
Ecosystems
WordPress
Weakness
CWE-862, CWE-863
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.