CVE-2024-12113: Youzify – BuddyPress Community, User Profile, Social Network & Membership Plugin for WordPress By KaineLabs <= 1.3.2 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Review Deletion
The Youzify – BuddyPress Community, User Profile, Social Network & Membership Plugin for WordPress plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check on the deleteuserreview() and deletereview() functions in all versions up to, and including, 1.3.2. This makes it possible for authenticated attackers, with Subscriber-level access and above, to delete other user's reviews.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-12113?
CVE-2024-12113 is classified as a high-severity vulnerability due to its potential for unauthorized data loss.
How do I fix CVE-2024-12113?
To fix CVE-2024-12113, update the Youzify plugin to version 1.3.3 or higher, which includes the necessary capability checks.
Who is affected by CVE-2024-12113?
CVE-2024-12113 affects all versions of the Youzify plugin for WordPress up to and including version 1.3.2.
What functions are involved in CVE-2024-12113?
CVE-2024-12113 involves vulnerabilities in the delete_user_review() and delete_review() functions due to missing capability checks.
Is CVE-2024-12113 known to be actively exploited?
As of now, there is no public indication that CVE-2024-12113 is being actively exploited in the wild.