github.com
https://github.com/karlemilnikka/CVE-2024-8349-and-CVE-2024-8350 CVE-2024-8349
HIGH
Uncanny Groups for LearnDash <= 6.1.0.1 - Authenticated (Group Leader+) Privilege Escalation
Record summary
CVE-2024-8349 has a selected CVSS score of 7.2 (high); EIP currently links 1 repository PoC.
Description
The Uncanny Groups for LearnDash plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including, 6.1.0.1. This is due to the plugin not properly restricting what users a group leader can edit. This makes it possible for authenticated attackers, with group leader-level access and above, to change admin account email addresses which can subsequently lead to admin account access.
Description source: CVE List
Exploitation context
Available material
- Repository PoCs
- 1
CISA SSVC decision
ExploitationNone
AutomatableNo
Technical impactTotal
CISA Coordinator · SSVC 2.0.3 · Evaluated Sep 25, 2024 · Source: CVE List
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
Uncanny Groups for LearnDashBrowse Uncanny Owl / Uncanny Groups for LearnDashDefault status: unaffected, unknown | CVE List | Through 6.1.0.1 | affected |
Proofs of concept
1Repository PoCs
GitHubkarlemilnikka/CVE-2024-8349-and-CVE-2024-8350Repository PoCby karlemilnikkaStars: 0Not analyzed1 file
References
3nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2024-8349 wordfence.com
https://www.wordfence.com/threat-intel/vulnerabilities/id/64cf0ae2-8d66-40d1-8bb6-0cab1dafab0d?source=cve