CVE-2024-0780

The Enjoy Social Feed plugin for WordPress website WordPress plugin through 6.2.2 does not have authorisation when resetting its database, allowing any authenticated users, such as subscriber to perform such action
Configurations

Configuration 1 (hide)

cpe:2.3:a:mediabetaprojects:enjoy_social_feed:*:*:*:*:*:wordpress:*:*

History

27 Feb 2025, 03:34

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 8.8
CWE CWE-862
CPE cpe:2.3:a:mediabetaprojects:enjoy_social_feed:*:*:*:*:*:wordpress:*:*
First Time Mediabetaprojects
Mediabetaprojects enjoy Social Feed
References () https://wpscan.com/vulnerability/be3045b1-72e6-450a-8dd2-4702a9328447/ - () https://wpscan.com/vulnerability/be3045b1-72e6-450a-8dd2-4702a9328447/ - Exploit, Third Party Advisory

21 Nov 2024, 08:47

Type Values Removed Values Added
Summary
  • (es) El complemento Enjoy Social Feed plugin for WordPress website de WordPress hasta 6.2.2 no tiene autorización para restablecer su base de datos, lo que permite que cualquier usuario autenticado, como un suscriptor, realice dicha acción.
References () https://wpscan.com/vulnerability/be3045b1-72e6-450a-8dd2-4702a9328447/ - () https://wpscan.com/vulnerability/be3045b1-72e6-450a-8dd2-4702a9328447/ -

18 Mar 2024, 19:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-03-18 19:15

Updated : 2025-03-14 17:15


NVD link : CVE-2024-0780

Mitre link : CVE-2024-0780

CVE.ORG link : CVE-2024-0780


JSON object : View

Products Affected

mediabetaprojects

  • enjoy_social_feed
CWE
CWE-862

Missing Authorization