Lucene search

K
cvelistPatchstackCVELIST:CVE-2024-38775
HistoryAug 01, 2024 - 8:48 p.m.

CVE-2024-38775 WordPress CTX Feed plugin <= 6.5.6 - Arbitrary Options Update vulnerability

2024-08-0120:48:05
CWE-269
Patchstack
www.cve.org
5
cve-2024-38775
wordpress
ctx feed
arbitrary options update
vulnerability
privilege management
webappick
privilege escalation

CVSS3

7.2

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

HIGH

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

EPSS

0

Percentile

9.4%

Improper Privilege Management vulnerability in WebAppick CTX Feed allows Privilege Escalation.This issue affects CTX Feed: from n/a through 6.5.6.

CNA Affected

[
  {
    "collectionURL": "https://wordpress.org/plugins",
    "defaultStatus": "unaffected",
    "packageName": "webappick-product-feed-for-woocommerce",
    "product": "CTX Feed",
    "vendor": "WebAppick",
    "versions": [
      {
        "changes": [
          {
            "at": "6.5.7",
            "status": "unaffected"
          }
        ],
        "lessThanOrEqual": "6.5.6",
        "status": "affected",
        "version": "n/a",
        "versionType": "custom"
      }
    ]
  }
]

CVSS3

7.2

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

HIGH

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

EPSS

0

Percentile

9.4%

Related for CVELIST:CVE-2024-38775