Vulnerability Description
The Uncanny Groups for LearnDash plugin for WordPress is vulnerable to user group add due to a missing capability check on the /wp-json/ulgm_management/v1/add_user/ REST API endpoint in all versions up to, and including, 6.1.0.1. This makes it possible for authenticated attackers, with group leader-level access and above, to add users to their group which ultimately allows them to leverage CVE-2024-8349 and gain admin access to the site.
CVSS Score
LOW
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Uncannyowl | Uncanny Groups For Learndash | < 6.1.1 |
Related Weaknesses (CWE)
References
- https://github.com/karlemilnikka/CVE-2024-8349-and-CVE-2024-8350ExploitThird Party Advisory
- https://www.wordfence.com/threat-intel/vulnerabilities/id/a38a58de-5f7d-4033-9a6Third Party Advisory
FAQ
What is CVE-2024-8350?
CVE-2024-8350 is a vulnerability with a CVSS score of 2.7 (LOW). The Uncanny Groups for LearnDash plugin for WordPress is vulnerable to user group add due to a missing capability check on the /wp-json/ulgm_management/v1/add_user/ REST API endpoint in all versions u...
How severe is CVE-2024-8350?
CVE-2024-8350 has been rated LOW with a CVSS base score of 2.7/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2024-8350?
Check the references section above for vendor advisories and patch information. Affected products include: Uncannyowl Uncanny Groups For Learndash.