CVE-2024-1158: Post Form – Registration Form – Profile Form for User Profiles – Frontend Content Forms for User Submissions (UGC) <= 2.8.7 - Missing Authorization
The Post Form – Registration Form – Profile Form for User Profiles – Frontend Content Forms for User Submissions (UGC) plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the buddyformsnewpage function in all versions up to, and including, 2.8.7. This makes it possible for authenticated attackers, with subscriber access or higher, to create pages with arbitrary titles. These pages are published.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2024-1158?
CVE-2024-1158 is classified as a critical vulnerability that allows unauthorized data modification.
How do I fix CVE-2024-1158?
To fix CVE-2024-1158, update the BuddyForms plugin to version 2.8.9 or later.
What versions of BuddyForms are affected by CVE-2024-1158?
CVE-2024-1158 affects all versions of BuddyForms up to and including 2.8.8.
What type of vulnerability is CVE-2024-1158?
CVE-2024-1158 is a vulnerability related to a missing capability check.
Who is impacted by CVE-2024-1158?
Users of the BuddyForms plugin in WordPress are impacted by CVE-2024-1158.