Vulnerability Description
The External Database Based Actions plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 0.1. This is due to a missing capability check in the 'edba_admin_handle' function. This makes it possible for authenticated attackers, with subscriber-level permissions and above, to update the plugin settings and log in as any existing user on the site, such as an administrator.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Cmorillas1 | External Database Based Actions | 0.1 |
Related Weaknesses (CWE)
References
- https://plugins.trac.wordpress.org/browser/external-database-based-actions/trunkProduct
- https://www.wordfence.com/threat-intel/vulnerabilities/id/d41a8c39-8b06-45b2-afeThird Party Advisory
FAQ
What is CVE-2024-10311?
CVE-2024-10311 is a vulnerability with a CVSS score of 7.5 (HIGH). The External Database Based Actions plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 0.1. This is due to a missing capability check in the 'edba_admin_hand...
How severe is CVE-2024-10311?
CVE-2024-10311 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2024-10311?
Check the references section above for vendor advisories and patch information. Affected products include: Cmorillas1 External Database Based Actions.