CVE-2024-32774
WordPress ProfileGrid plugin <= 5.8.2 - Group Members Limit Bypass vulnerability
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
Improper Restriction of Excessive Authentication Attempts vulnerability in Metagauss ProfileGrid allows Removing Important Client Functionality.This issue affects ProfileGrid : from n/a through 5.8.2.
La vulnerabilidad de restricción incorrecta de intentos de autenticación excesivos en Metagauss ProfileGrid permite eliminar funciones importantes del cliente. Este problema afecta a ProfileGrid: desde n/a hasta 5.8.2.
The ProfileGrid – User Profiles, Memberships, Groups and Communities plugin for WordPress is vulnerable to group limit bypass in all versions up to, and including, 5.8.2. This is due to the plugin not properly verifying the limits of a group before adding a member. This makes it possible for authenticated attackers, with subscriber-level access and above, to bypass group limits.
CVSS Scores
SSVC
- Decision:Track
Timeline
- 2024-04-18 CVE Reserved
- 2024-04-22 CVE Published
- 2024-05-18 EPSS Updated
- 2024-08-02 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-285: Improper Authorization
- CWE-307: Improper Restriction of Excessive Authentication Attempts
CAPEC
- CAPEC-207: Removing Important Client Functionality
References (1)
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Profilegrid User Profiles Groups And Communities Search vendor "Profilegrid User Profiles Groups And Communities" | Profilegrid User Profiles Groups And Communities Search vendor "Profilegrid User Profiles Groups And Communities" for product "Profilegrid User Profiles Groups And Communities" | >= 0.0.0 <= 5.8.2 Search vendor "Profilegrid User Profiles Groups And Communities" for product "Profilegrid User Profiles Groups And Communities" and version " >= 0.0.0 <= 5.8.2" | en |
Affected
|