mirror of
https://github.com/0xMarcio/cve.git
synced 2025-11-28 18:48:49 +00:00
21 lines
1.4 KiB
Markdown
21 lines
1.4 KiB
Markdown
### [CVE-2024-9583](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-9583)
|
||

|
||

|
||

|
||

|
||
|
||
### Description
|
||
|
||
The RSS Aggregator – RSS Import, News Feeds, Feed to Post, and Autoblogging plugin for WordPress is vulnerable to unauthorized use of functionality due to a missing capability check on the wprss_ajax_send_premium_support function in all versions up to, and including, 4.23.12. This makes it possible for authenticated attackers, with Subscriber-level access and above, to send premium support requests with an attacker-controlled subject line and email address to support allowing them to impersonate the site owner. License information may also be leaked.
|
||
|
||
### POC
|
||
|
||
#### Reference
|
||
- https://www.wordfence.com/threat-intel/vulnerabilities/id/126c77fa-11c5-431f-8fc9-0375ed6c8a91?source=cve
|
||
|
||
#### Github
|
||
- https://github.com/20142995/nuclei-templates
|
||
- https://github.com/cyb3r-w0lf/nuclei-template-collection
|
||
- https://github.com/fkie-cad/nvd-json-data-feeds
|
||
|