CVE-2024-3237: ConvertPlug <= 3.5.25 - Missing Authorization to Authenticated (Subscriber+) Limited Arbitrary Options Update
The ConvertPlug plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the cpdismissnotice() function in all versions up to, and including, 3.5.25. This makes it possible for authenticated attackers, with subscriber-level access and above, to update arbitrary option values to true.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-3237?
CVE-2024-3237 is considered a medium severity vulnerability due to the potential for unauthorized data modification by authenticated attackers.
How do I fix CVE-2024-3237?
To fix CVE-2024-3237, update the ConvertPlug plugin to version 3.5.26 or later where the vulnerability has been addressed.
Who is affected by CVE-2024-3237?
CVE-2024-3237 affects all versions of the ConvertPlug plugin up to and including version 3.5.25.
What types of attacks can occur due to CVE-2024-3237?
CVE-2024-3237 allows authenticated attackers with subscriber-level access to modify data, potentially leading to unauthorized changes on a WordPress site.
What software does CVE-2024-3237 impact?
CVE-2024-3237 impacts the ConvertPlug plugin for WordPress, specifically versions up to and including 3.5.25.