CVE-2024-11844: IdeaPush <= 8.71 - Missing Authorization to Board Term Deletion
The IdeaPush plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the ideapushtaxonomysaveroutine function in all versions up to, and including, 8.71. This makes it possible for authenticated attackers, with Subscriber-level access and above, to delete terms for the "boards" taxonomy.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2024-11844?
CVE-2024-11844 has a high severity level due to the potential for unauthorized data modification by authenticated attackers.
How do I fix CVE-2024-11844?
To fix CVE-2024-11844, update the IdeaPush plugin to the latest version beyond 8.71 which addresses this vulnerability.
Who is affected by CVE-2024-11844?
CVE-2024-11844 affects all versions of the IdeaPush plugin for WordPress up to and including version 8.71.
What types of attacks can CVE-2024-11844 enable?
CVE-2024-11844 enables authenticated attackers to modify data without proper authorization, potentially compromising site integrity.
Is user authentication sufficient to protect against CVE-2024-11844?
No, user authentication alone is insufficient against CVE-2024-11844, as it allows authenticated users to exploit the missing capability check.