CVE-2024-1110

The Podlove Podcast Publisher plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the init() function in all versions up to, and including, 4.0.11. This makes it possible for unauthenticated attackers to import the plugin's settings.
Configurations

Configuration 1 (hide)

cpe:2.3:a:podlove:podlove_podcast_publisher:*:*:*:*:*:wordpress:*:*

History

10 Feb 2024, 04:13

Type Values Removed Values Added
CPE cpe:2.3:a:podlove:podlove_podcast_publisher:*:*:*:*:*:wordpress:*:*
Summary
  • (es) El complemento Podlove Podcast Publisher para WordPress es vulnerable a modificaciones no autorizadas de datos debido a una falta de verificación de capacidad en la función init() en todas las versiones hasta la 4.0.11 incluida. Esto hace posible que atacantes no autenticados importen la configuración del complemento.
First Time Podlove podlove Podcast Publisher
Podlove
References () https://github.com/podlove/podlove-publisher/commit/7873ff520631087e2f10737860cdcd64d53187ba - () https://github.com/podlove/podlove-publisher/commit/7873ff520631087e2f10737860cdcd64d53187ba - Patch
References () https://plugins.trac.wordpress.org/changeset?sfp_email=&sfph_mail=&reponame=&old=3032008%40podlove-podcasting-plugin-for-wordpress&new=3032008%40podlove-podcasting-plugin-for-wordpress&sfp_email=&sfph_mail= - () https://plugins.trac.wordpress.org/changeset?sfp_email=&sfph_mail=&reponame=&old=3032008%40podlove-podcasting-plugin-for-wordpress&new=3032008%40podlove-podcasting-plugin-for-wordpress&sfp_email=&sfph_mail= - Patch
References () https://www.wordfence.com/threat-intel/vulnerabilities/id/2c9cf461-572c-4be8-96e6-659acf3208f3?source=cve - () https://www.wordfence.com/threat-intel/vulnerabilities/id/2c9cf461-572c-4be8-96e6-659acf3208f3?source=cve - Third Party Advisory
CWE CWE-862

07 Feb 2024, 11:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-02-07 11:15

Updated : 2024-02-10 04:13


NVD link : CVE-2024-1110

Mitre link : CVE-2024-1110

CVE.ORG link : CVE-2024-1110


JSON object : View

Products Affected

podlove

  • podlove_podcast_publisher
CWE
CWE-862

Missing Authorization