CVE-2024-0780
Enjoy Social Feed <= 6.2.2 - Subscriber+ Plugin Database Reset
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
1Exploited in Wild
-Decision
Descriptions
The Enjoy Social Feed plugin for WordPress website WordPress plugin through 6.2.2 does not have authorisation when resetting its database, allowing any authenticated users, such as subscriber to perform such action
El complemento Enjoy Social Feed plugin for WordPress website de WordPress hasta 6.2.2 no tiene autorización para restablecer su base de datos, lo que permite que cualquier usuario autenticado, como un suscriptor, realice dicha acción.
The Enjoy Social Feed plugin for WordPress website plugin for WordPress is vulnerable to unauthorized access and modification of data due to a missing capability check when accessing the enjoyinstagram_plugin_options page in all versions up to, and including, 6.2.2. This makes it possible for authenticated attackers, with subscriber-level access and above, to reset the plugin's database.
CVSS Scores
SSVC
- Decision:Track*
Timeline
- 2024-01-22 CVE Reserved
- 2024-02-20 CVE Published
- 2024-03-19 EPSS Updated
- 2024-08-28 CVE Updated
- 2024-08-28 First Exploit
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
- CWE-862: Missing Authorization
CAPEC
References (1)
URL | Tag | Source |
---|
URL | Date | SRC |
---|---|---|
https://wpscan.com/vulnerability/be3045b1-72e6-450a-8dd2-4702a9328447 | 2024-08-28 |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Unknown Search vendor "Unknown" | Enjoy Social Feed Plugin For WordPress Website Search vendor "Unknown" for product "Enjoy Social Feed Plugin For WordPress Website" | <= 6.2.2 Search vendor "Unknown" for product "Enjoy Social Feed Plugin For WordPress Website" and version " <= 6.2.2" | en |
Affected
|