CVE-2024-13370: Youzify – BuddyPress Community, User Profile, Social Network & Membership Plugin for WordPress <= 1.3.3 - Missing Authorization to Authenticated (Subscriber+) Limited Options Update (save_addon_key_license)
The Youzify – BuddyPress Community, User Profile, Social Network & Membership Plugin for WordPress plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on the saveaddonkeylicense() function in all versions up to, and including, 1.3.3. This makes it possible for authenticated attackers, with Subscriber-level access and above, to update arbitrary options to a value of a valid license key.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-13370?
CVE-2024-13370 has a high severity due to the potential for unauthorized access.
How do I fix CVE-2024-13370?
To fix CVE-2024-13370, update the Youzify BuddyPress Community plugin to version 1.3.3 or later.
What versions are affected by CVE-2024-13370?
CVE-2024-13370 affects all versions of the Youzify plugin up to and including version 1.3.2.
What is the nature of the vulnerability in CVE-2024-13370?
The vulnerability in CVE-2024-13370 is due to a missing capability check that allows unauthorized access.
Who is the vendor for CVE-2024-13370?
The vendor for CVE-2024-13370 is Youzify, which is associated with the BuddyPress Community plugin.