CVE-2024-3895: WP Datepicker <= 2.1.0 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Options Update
The WP Datepicker plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the wpdpaddnewdatepickerajax() function in all versions up to, and including, 2.1.0. This makes it possible for authenticated attackers, with subscriber-level access and above, to update arbitrary options that can be used for privilege escalation. This was partially patched in 2.0.9 and 2.1.0, and fully patched in 2.1.1.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2024-3895?
CVE-2024-3895 is a high-severity vulnerability that allows authenticated attackers to modify data due to a missing capability check in the WP Datepicker plugin.
How do I fix CVE-2024-3895?
To fix CVE-2024-3895, upgrade the WP Datepicker plugin to version 2.1.1 or later.
Who is affected by CVE-2024-3895?
CVE-2024-3895 affects all versions of the WP Datepicker plugin up to and including version 2.1.0.
What types of attacks can CVE-2024-3895 enable?
CVE-2024-3895 can enable authenticated attackers with subscriber-level access to modify data in the WordPress site.
What plugin is vulnerable in CVE-2024-3895?
CVE-2024-3895 affects the WP Datepicker plugin for WordPress.