Record summary

CVE-2024-8350 has a selected CVSS score of 2.7 (low); EIP currently links 1 repository PoC.

Description

The Uncanny Groups for LearnDash plugin for WordPress is vulnerable to user group add due to a missing capability check on the /wp-json/ulgm_management/v1/add_user/ REST API endpoint in all versions up to, and including, 6.1.0.1. This makes it possible for authenticated attackers, with group leader-level access and above, to add users to their group which ultimately allows them to leverage CVE-2024-8349 and gain admin access to the site.

Description source: CVE List

Exploitation context

Available material

Repository PoCs
1

CISA SSVC decision

ExploitationNone
AutomatableNo
Technical impactPartial

CISA Coordinator · SSVC 2.0.3 · Evaluated Sep 25, 2024 · Source: CVE List

Affected products and versions

1
ProductSourceVersion rangeStatus

Default status: unaffected

CVE ListThrough 6.1.0.1affected

Proofs of concept

1

Repository PoCs

GitHubkarlemilnikka/CVE-2024-8349-and-CVE-2024-8350Repository PoCby karlemilnikkaStars: 0Not analyzed1 file

7.3 KiB · linked to 2 vulnerabilities

GitHub

PoC details

References

3