| |
Vulnerability CVE-2024-9860
Published: 2024-10-12
Description: |
The Bridge Core plugin for WordPress is vulnerable to unauthorized modification of data or loss of data due to a missing capability check on the 'import_action' and 'install_plugin_per_demo' functions in versions up to, and including, 3.3. This makes it possible for authenticated attackers with subscriber-level permissions or above, to delete or change plugin settings, import demo data, and install limited plugins. |
Type:
CWE-862 (Missing Authorization)
References: |
https://www.wordfence.com/threat-intel/vulnerabilities/id/968d5d31-2592-4bed-9d18-5877f0d6062e?source=cve
https://themeforest.net/item/bridge-creative-multipurpose-wordpress-theme/7315054
|
|
|
closedb();
?>
Copyright 2024, cxsecurity.com
|
|
|