CVE-2024-0366: Starbox – the Author Box for Humans <= 3.4.7 - Insecure Direct Object Reference
The Starbox – the Author Box for Humans plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 3.4.7 via the action function due to missing validation on a user controlled key. This makes it possible for subscribers to view plugin preferences and potentially other user settings.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-0366?
CVE-2024-0366 is considered a medium severity vulnerability due to the potential for unauthorized access to sensitive plugin preferences.
How do I fix CVE-2024-0366?
To fix CVE-2024-0366, update the Starbox plugin to version 3.4.8 or later where the vulnerability is addressed.
Which versions are affected by CVE-2024-0366?
CVE-2024-0366 affects all versions of the Starbox plugin up to and including version 3.4.7.
What type of vulnerability is CVE-2024-0366?
CVE-2024-0366 is categorized as an Insecure Direct Object Reference vulnerability.
Who can exploit CVE-2024-0366?
Subscribers with access to the Starbox plugin can exploit CVE-2024-0366 due to the lack of validation on user-controlled keys.