CVE-2024-11496: Infility Global <= 2.9.8 - Authenticated (Subscriber+) Missing Authorization to Plugin Options Update
The Infility Global plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the infilityglobalajax function in all versions up to, and including, 2.9.8. This makes it possible for authenticated attackers, with Subscriber-level access and above, to update plugin options and potentially break the site.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-11496?
CVE-2024-11496 has a high severity rating due to its potential for unauthorized data modification.
How do I fix CVE-2024-11496?
To fix CVE-2024-11496, upgrade the Infility Global plugin to version 2.9.9 or later, which includes the necessary capability checks.
Who is affected by CVE-2024-11496?
Authenticated users with Subscriber-level access in WordPress installations using Infility Global versions up to 2.9.8 are affected by CVE-2024-11496.
What versions of Infility Global are vulnerable to CVE-2024-11496?
All versions of Infility Global up to and including 2.9.8 are vulnerable to CVE-2024-11496.
What kind of attack does CVE-2024-11496 facilitate?
CVE-2024-11496 facilitates unauthorized modification of data, allowing authenticated attackers to exploit the missing capability check.