CVE-2024-13368: Youzify – BuddyPress Community, User Profile, Social Network & Membership Plugin for WordPress <= 1.3.4 - Missing Authorization to Authenticated (Subscriber+) Limited Options Update
The Youzify – BuddyPress Community, User Profile, Social Network & Membership Plugin for WordPress plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on the youzifyofferbanner() function in all versions up to, and including, 1.3.4. This makes it possible for authenticated attackers, with Subscriber-level access and above, to update arbitrary site options to a value of one.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-13368?
CVE-2024-13368 is considered a high severity vulnerability due to the potential for unauthorized access.
How do I fix CVE-2024-13368?
To fix CVE-2024-13368, update the Youzify plugin to version 1.3.3 or later.
What versions of the Youzify plugin are affected by CVE-2024-13368?
CVE-2024-13368 affects all versions of the Youzify plugin up to and including version 1.3.2.
What kind of access does CVE-2024-13368 allow?
CVE-2024-13368 allows unauthorized users to access certain functionalities of the Youzify plugin due to a missing capability check.
Who is the vendor responsible for the Youzify plugin associated with CVE-2024-13368?
The vendor responsible for the Youzify plugin is KaineLabs.