CVE-2024-10216: WP User Manager – User Profile Builder & Membership <= 2.9.11 - Missing Authorization to Carbon Fields Custom Sidebar Addition/Removal
The WP User Manager – User Profile Builder & Membership plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'addsidebar' and 'removesidebar' functions in all versions up to, and including, 2.9.11. This makes it possible for authenticated attackers, with Subscriber-level access and above, to add or remove a Carbon Fields custom sidebar if the Carbon Fields (carbon-fields) plugin is installed.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2024-10216?
CVE-2024-10216 has a medium severity rating due to unauthorized data modification risks.
How do I fix CVE-2024-10216?
To fix CVE-2024-10216, update the WP User Manager – User Profile Builder & Membership plugin to version 2.9.12 or later.
What versions are affected by CVE-2024-10216?
CVE-2024-10216 affects all versions of the WP User Manager plugin up to and including 2.9.11.
What types of actions can be exploited in CVE-2024-10216?
CVE-2024-10216 allows unauthorized users to execute the 'add_sidebar' and 'remove_sidebar' actions without proper capability checks.
Who is impacted by CVE-2024-10216?
Users of the WP User Manager – User Profile Builder & Membership plugin on WordPress sites are impacted by CVE-2024-10216.