Record summary

CVE-2024-8349 has a selected CVSS score of 7.2 (high); EIP currently links 1 repository PoC.

Description

The Uncanny Groups for LearnDash plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including, 6.1.0.1. This is due to the plugin not properly restricting what users a group leader can edit. This makes it possible for authenticated attackers, with group leader-level access and above, to change admin account email addresses which can subsequently lead to admin account access.

Description source: CVE List

Exploitation context

Available material

Repository PoCs
1

CISA SSVC decision

ExploitationNone
AutomatableNo
Technical impactTotal

CISA Coordinator · SSVC 2.0.3 · Evaluated Sep 25, 2024 · Source: CVE List

Affected products and versions

1
ProductSourceVersion rangeStatus

Default status: unaffected, unknown

CVE ListThrough 6.1.0.1affected

Proofs of concept

1

Repository PoCs

GitHubkarlemilnikka/CVE-2024-8349-and-CVE-2024-8350Repository PoCby karlemilnikkaStars: 0Not analyzed1 file

7.3 KiB · linked to 2 vulnerabilities

GitHub

PoC details

References

3