Lucene search

K
vulnrichmentPatchstackVULNRICHMENT:CVE-2024-31237
HistoryMay 17, 2024 - 8:53 a.m.

CVE-2024-31237 WordPress s2Member plugin <= 240315 - Privilege Escalation vulnerability

2024-05-1708:53:54
CWE-269
Patchstack
github.com
1
cve-2024-31237
wordpress
s2member plugin
privilege escalation
vulnerability
wp sharks
improper privilege management

7.5 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

6.9 Medium

AI Score

Confidence

High

0.0004 Low

EPSS

Percentile

9.1%

Improper Privilege Management vulnerability in WP Sharks s2Member Pro allows Privilege Escalation.This issue affects s2Member Pro: from n/a through 240315.

CNA Affected

[
  {
    "collectionURL": "https://wordpress.org/plugins",
    "defaultStatus": "unaffected",
    "packageName": "s2member",
    "product": "s2Member Pro",
    "vendor": "WP Sharks",
    "versions": [
      {
        "changes": [
          {
            "at": "240325",
            "status": "unaffected"
          }
        ],
        "lessThanOrEqual": "240315",
        "status": "affected",
        "version": "n/a",
        "versionType": "custom"
      }
    ]
  }
]

7.5 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

6.9 Medium

AI Score

Confidence

High

0.0004 Low

EPSS

Percentile

9.1%

Related for VULNRICHMENT:CVE-2024-31237