CVE-2024-7624

T

he Zephyr Project Manager plugin for WordPress is vulnerable to limited privilege escalation in all versions up to, and including, 3.3.101. This is due to the plugin not properly checking a users capabilities before allowing them to enable access to the plugin's settings through the update_user_access() function. This makes it possible for authenticated attackers, with subscriber-level access and above, to grant themselves full access to the plugin's settings.

Configurations

Configuration 1 (hide)

cpe:2.3:a:zephyr-one:zephyr_project_manager:*:*:*:*:*:wordpress:*:*

History

11 Feb 2025, 20:13

Type Values Removed Values Added
First Time Zephyr-one
Zephyr-one zephyr Project Manager
CWE CWE-863
CPE cpe:2.3:a:zephyr-one:zephyr_project_manager:*:*:*:*:*:wordpress:*:*
References () https://plugins.trac.wordpress.org/browser/zephyr-project-manager/trunk/includes/Base/AjaxHandler.php?rev=3111536#L2464 - () https://plugins.trac.wordpress.org/browser/zephyr-project-manager/trunk/includes/Base/AjaxHandler.php?rev=3111536#L2464 - Product
References () https://plugins.trac.wordpress.org/changeset/3134404/ - () https://plugins.trac.wordpress.org/changeset/3134404/ - Patch
References () https://www.wordfence.com/threat-intel/vulnerabilities/id/b9ef344d-cd56-43f9-b185-de83a92800de?source=cve - () https://www.wordfence.com/threat-intel/vulnerabilities/id/b9ef344d-cd56-43f9-b185-de83a92800de?source=cve - Third Party Advisory

15 Aug 2024, 13:01

Type Values Removed Values Added
New CVE

Information

Published : 2024-08-15 03:15

Updated : 2025-02-11 20:13


NVD link : CVE-2024-7624

Mitre link : CVE-2024-7624

CVE.ORG link : CVE-2024-7624


JSON object : View

CWE
CWE-285

Improper Authorization

CWE-863

Incorrect Authorization