The Bridge Core plugin for WordPress is vulnerable to unauthorized modification of data or loss of data due to a missing capability check on the 'import_action' and 'install_plugin_per_demo' functions in versions up to, and including, 3.3. This makes it possible for authenticated attackers with subscriber-level permissions or above, to delete or change plugin settings, import demo data, and install limited plugins.
Metrics
Affected Vendors & Products
References
History
Tue, 15 Oct 2024 18:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Qode
Qode bridge Core |
|
| CPEs | cpe:2.3:a:qode:bridge_core:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Qode
Qode bridge Core |
|
| Metrics |
ssvc
|
Sat, 12 Oct 2024 02:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The Bridge Core plugin for WordPress is vulnerable to unauthorized modification of data or loss of data due to a missing capability check on the 'import_action' and 'install_plugin_per_demo' functions in versions up to, and including, 3.3. This makes it possible for authenticated attackers with subscriber-level permissions or above, to delete or change plugin settings, import demo data, and install limited plugins. | |
| Title | Bridge Core <= 3.3 - Missing Authorization to Authenticated (Subscriber+) Demo Import | |
| Weaknesses | CWE-862 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: Wordfence
Published: 2024-10-12T02:05:43.175Z
Updated: 2024-10-15T17:40:18.621Z
Reserved: 2024-10-11T12:45:07.126Z
Link: CVE-2024-9860
Updated: 2024-10-15T17:39:44.875Z
Status : Awaiting Analysis
Published: 2024-10-12T03:15:02.757
Modified: 2024-10-15T12:57:46.880
Link: CVE-2024-9860
No data.