The WP Crowdfunding plugin for WordPress is vulnerable to unauthorized plugin installation due to a missing capability check on the install_woocommerce_plugin() function action in all versions up to, and including, 2.1.12. This makes it possible for authenticated attackers, with Subscriber-level access and above, to install WooCommerce. This has a limited impact on most sites because WooCommerce is a requirement.
Metrics
Affected Vendors & Products
References
History
Tue, 11 Feb 2025 14:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Themeum
Themeum wp Crowdfunding |
|
| CPEs | cpe:2.3:a:themeum:wp_crowdfunding:*:*:*:*:*:wordpress:*:* | |
| Vendors & Products |
Themeum
Themeum wp Crowdfunding |
Mon, 16 Dec 2024 20:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Fri, 13 Dec 2024 08:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The WP Crowdfunding plugin for WordPress is vulnerable to unauthorized plugin installation due to a missing capability check on the install_woocommerce_plugin() function action in all versions up to, and including, 2.1.12. This makes it possible for authenticated attackers, with Subscriber-level access and above, to install WooCommerce. This has a limited impact on most sites because WooCommerce is a requirement. | |
| Title | WP Crowdfunding <= 2.1.12 - Missing Authorization to Authenticated (Subscriber+) WooCommerce Installation | |
| Weaknesses | CWE-862 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: Wordfence
Published: 2024-12-13T08:24:50.235Z
Updated: 2024-12-16T20:07:27.042Z
Reserved: 2024-11-27T17:02:30.059Z
Link: CVE-2024-11911
Updated: 2024-12-16T19:39:57.439Z
Status : Analyzed
Published: 2024-12-13T09:15:07.083
Modified: 2025-02-11T14:21:42.667
Link: CVE-2024-11911
No data.
ReportizFlow