Vulnerability CVE-2024-9860


Published: 2024-10-12

Description:
The Bridge Core plugin for WordPress is vulnerable to unauthorized modification of data or loss of data due to a missing capability check on the 'import_action' and 'install_plugin_per_demo' functions in versions up to, and including, 3.3. This makes it possible for authenticated attackers with subscriber-level permissions or above, to delete or change plugin settings, import demo data, and install limited plugins.

Type:

CWE-862

(Missing Authorization)

 References:
https://www.wordfence.com/threat-intel/vulnerabilities/id/968d5d31-2592-4bed-9d18-5877f0d6062e?source=cve
https://themeforest.net/item/bridge-creative-multipurpose-wordpress-theme/7315054

Copyright 2024, cxsecurity.com

 

Back to Top