The WCFM – Frontend Manager for WooCommerce along with Bookings Subscription Listings Compatible plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 6.7.12 via the WCFM_Customers_Manage_Controller::processing function due to missing validation on the ID user controlled key. This makes it possible for authenticated attackers, with subscriber/customer-level access and above, to change the email address of administrator user accounts which allows them to reset the password and access the administrator account.
                
            Metrics
Affected Vendors & Products
References
        History
                    Sat, 12 Jul 2025 13:45:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| Metrics | epss 
 | epss 
 | 
Wed, 02 Oct 2024 18:45:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| CPEs | cpe:2.3:a:wclovers:frontend_manager_for_woocommerce_along_with_bookings_subscription_listings_compatible:*:*:*:*:*:wordpress:*:* | 
Wed, 25 Sep 2024 14:30:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| First Time appeared | Wclovers Wclovers frontend Manager For Woocommerce Along With Bookings Subscription Listings Compatible | |
| CPEs | cpe:2.3:a:wclovers:frontend_manager_for_woocommerce_along_with_bookings_subscription_listings_compatible:*:*:*:*:*:*:*:* | |
| Vendors & Products | Wclovers Wclovers frontend Manager For Woocommerce Along With Bookings Subscription Listings Compatible | |
| Metrics | ssvc 
 | 
Wed, 25 Sep 2024 07:00:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| Description | The WCFM – Frontend Manager for WooCommerce along with Bookings Subscription Listings Compatible plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 6.7.12 via the WCFM_Customers_Manage_Controller::processing function due to missing validation on the ID user controlled key. This makes it possible for authenticated attackers, with subscriber/customer-level access and above, to change the email address of administrator user accounts which allows them to reset the password and access the administrator account. | |
| Title | WCFM – Frontend Manager for WooCommerce along with Bookings Subscription Listings Compatible <= 6.7.12 - Insecure Direct Object Reference to Account Takeover/Privilege Escalation | |
| Weaknesses | CWE-639 | |
| References |  | 
 | 
| Metrics | cvssV3_1 
 | 
 MITRE
                        MITRE
                    Status: PUBLISHED
Assigner: Wordfence
Published: 2024-09-25T06:49:01.430Z
Updated: 2024-09-25T13:21:08.505Z
Reserved: 2024-08-28T20:42:11.811Z
Link: CVE-2024-8290
 Vulnrichment
                        Vulnrichment
                    Updated: 2024-09-25T13:21:02.391Z
 NVD
                        NVD
                    Status : Analyzed
Published: 2024-09-25T07:15:03.663
Modified: 2024-10-02T18:23:25.890
Link: CVE-2024-8290
 Redhat
                        Redhat
                    No data.
 ReportizFlow
ReportizFlow