2024-12-08 03:06:42 +00:00

60 lines
2.6 KiB
JSON

{
"id": "CVE-2024-6167",
"sourceIdentifier": "security@wordfence.com",
"published": "2024-07-09T09:15:09.373",
"lastModified": "2024-11-21T09:49:06.433",
"vulnStatus": "Awaiting Analysis",
"cveTags": [],
"descriptions": [
{
"lang": "en",
"value": "The Just Custom Fields plugin for WordPress is vulnerable to unauthorized access of functionality due to a missing capability check on several AJAX functions in all versions up to, and including, 3.3.2. This makes it possible for authenticated attackers, with Subscriber-level access and above, to invoke this functionality intended for admin users. This enables subscribers to manage field groups, change visibility of items among other things."
},
{
"lang": "es",
"value": " El complemento Just Custom Fields para WordPress es vulnerable al acceso no autorizado de funcionalidad debido a una falta de verificaci\u00f3n de capacidad en varias funciones AJAX en todas las versiones hasta la 3.3.2 incluida. Esto hace posible que los atacantes autenticados, con acceso de nivel de suscriptor y superior, invoquen esta funcionalidad destinada a usuarios administradores. Esto permite a los suscriptores administrar grupos de campos, cambiar la visibilidad de los elementos, entre otras cosas."
}
],
"metrics": {
"cvssMetricV31": [
{
"source": "security@wordfence.com",
"type": "Secondary",
"cvssData": {
"version": "3.1",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N",
"baseScore": 4.3,
"baseSeverity": "MEDIUM",
"attackVector": "NETWORK",
"attackComplexity": "LOW",
"privilegesRequired": "LOW",
"userInteraction": "NONE",
"scope": "UNCHANGED",
"confidentialityImpact": "NONE",
"integrityImpact": "LOW",
"availabilityImpact": "NONE"
},
"exploitabilityScore": 2.8,
"impactScore": 1.4
}
]
},
"references": [
{
"url": "https://wordpress.org/plugins/just-custom-fields",
"source": "security@wordfence.com"
},
{
"url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/14d71220-be60-498d-92ca-055f1c237060?source=cve",
"source": "security@wordfence.com"
},
{
"url": "https://wordpress.org/plugins/just-custom-fields",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/14d71220-be60-498d-92ca-055f1c237060?source=cve",
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
]
}