Vulnerability Description
The Email Log plugin for WordPress is vulnerable to Unauthenticated Hook Injection in all versions up to, and including, 2.4.8 via the check_nonce function. This makes it possible for unauthenticated attackers to execute actions with hooks in WordPress under certain circumstances. The action the attacker wishes to execute needs to have a nonce check, and the nonce needs to be known to the attacker. Furthermore, the absence of a capability check is a requirement.
CVSS Score
HIGH
Related Weaknesses (CWE)
References
- https://plugins.trac.wordpress.org/changeset?sfp_email=&sfph_mail=&reponame=&old
- https://wordpress.org/plugins/email-log/
- https://www.wordfence.com/threat-intel/vulnerabilities/id/fd15268f-7e06-4e0d-baa
- https://plugins.trac.wordpress.org/changeset?sfp_email=&sfph_mail=&reponame=&old
- https://wordpress.org/plugins/email-log/
- https://www.wordfence.com/threat-intel/vulnerabilities/id/fd15268f-7e06-4e0d-baa
FAQ
What is CVE-2024-0867?
CVE-2024-0867 is a vulnerability with a CVSS score of 8.1 (HIGH). The Email Log plugin for WordPress is vulnerable to Unauthenticated Hook Injection in all versions up to, and including, 2.4.8 via the check_nonce function. This makes it possible for unauthenticated ...
How severe is CVE-2024-0867?
CVE-2024-0867 has been rated HIGH with a CVSS base score of 8.1/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2024-0867?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.