Lucene search

K
prionPRIOn knowledge basePRION:CVE-2024-1110
HistoryFeb 07, 2024 - 11:15 a.m.

Design/Logic Flaw

2024-02-0711:15:00
PRIOn knowledge base
www.prio-n.com
4
design flaw
logic flaw
wordpress plugin
unauthorized modification
data vulnerability
capability check
version 4.0.11
unauthenticated attackers
plugin settings
nvd

7 High

AI Score

Confidence

Low

0.001 Low

EPSS

Percentile

28.6%

The Podlove Podcast Publisher plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the init() function in all versions up to, and including, 4.0.11. This makes it possible for unauthenticated attackers to import the plugin’s settings.

CPENameOperatorVersion
podlove_podcast_publisherle4.0.11

7 High

AI Score

Confidence

Low

0.001 Low

EPSS

Percentile

28.6%

Related for PRION:CVE-2024-1110