Record summary

CVE-2024-0710 has a selected CVSS score of 5.3 (medium); EIP currently links 1 repository PoC.

Description

The GP Unique ID plugin for WordPress is vulnerable to Unique ID Modification in all versions up to, and including, 1.5.5. This is due to insufficient input validation. This makes it possible for unauthenticated attackers to tamper with the generation of a unique ID on a form submission and replace the generated unique ID with a user-controlled one, leading to a loss of integrity in cases where the ID's uniqueness is relied upon in a security-specific context.

Description source: CVE List

Exploitation context

Available material

Repository PoCs
1

CISA SSVC decision

ExploitationNone
AutomatableYes
Technical impactPartial

CISA Coordinator · SSVC 2.0.3 · Evaluated May 2, 2024 · Source: CVE List

Affected products and versions

1
ProductSourceVersion rangeStatus

Default status: unaffected, unknown

CVE ListThrough 1.5.5affected
1.5.5affected

Proofs of concept

1

Repository PoCs

GitHubkarlemilnikka/CVE-2024-0710Repository PoCby karlemilnikkaStars: 1Not analyzed1 file

3.1 KiB

GitHub

PoC details

References

4