CVE-2024-0324: User Profile Builder <= 3.10.8 - Missing Authorization to Plugin Settings Change via wppb_two_factor_authentication_settings_update
The User Profile Builder – Beautiful User Registration Forms, User Profiles & User Role Editor plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'wppbtwofactorauthenticationsettingsupdate' function in all versions up to, and including, 3.10.8. This makes it possible for unauthenticated attackers to enable or disable the 2FA functionality present in the Premium version of the plugin for arbitrary user roles.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2024-0324?
CVE-2024-0324 has a high severity due to the potential for unauthorized modification of user data.
How do I fix CVE-2024-0324?
To fix CVE-2024-0324, update the User Profile Builder plugin to the latest version that includes capability checks.
Which versions of the User Profile Builder plugin are affected by CVE-2024-0324?
CVE-2024-0324 affects all versions of the User Profile Builder plugin up to and including 3.10.8.
What type of vulnerability is CVE-2024-0324?
CVE-2024-0324 is a data modification vulnerability caused by a missing capability check.
Can CVE-2024-0324 lead to data breaches?
Yes, CVE-2024-0324 can lead to data breaches if attackers exploit the unauthorized data modification capability.