CVE-2024-1170: Post Form – Registration Form – Profile Form for User Profiles – Frontend Content Forms for User Submissions (UGC) <= 2.8.7 - Missing Authorization to Unauthenticated Media Deletion
The Post Form – Registration Form – Profile Form for User Profiles – Frontend Content Forms for User Submissions (UGC) plugin for WordPress is vulnerable to unauthorized media file deletion due to a missing capability check on the handledeletedmedia function in all versions up to, and including, 2.8.7. This makes it possible for unauthenticated attackers to delete arbitrary media files.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-1170?
The severity of CVE-2024-1170 is considered to be high due to the potential for unauthorized media file deletion.
How do I fix CVE-2024-1170?
To fix CVE-2024-1170, update the Post Form – Registration Form – Profile Form for User Profiles plugin to version 2.8.8 or later.
What versions are affected by CVE-2024-1170?
CVE-2024-1170 affects all versions of the Post Form plugin up to and including version 2.8.7.
What is the impact of CVE-2024-1170?
The impact of CVE-2024-1170 includes the risk of unauthorized users deleting media files from the website.
Is CVE-2024-1170 specific to certain WordPress installations?
CVE-2024-1170 affects all installations of WordPress that are using the vulnerable versions of the Post Form plugin.