First published: Tue Jun 04 2024(Updated: )
The buddyboss-platform WordPress plugin before 2.6.0 contains an IDOR vulnerability that allows a user to like a private post by manipulating the ID included in the request
Credit: contact@wpscan.com
Affected Software | Affected Version | How to fix |
---|---|---|
BuddyBoss Platform | <2.6.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-4750 has a high severity rating due to its potential to allow unauthorized actions on private posts.
To fix CVE-2024-4750, update the BuddyBoss Platform plugin to version 2.6.0 or later.
CVE-2024-4750 affects the BuddyBoss Platform WordPress plugin prior to version 2.6.0.
An IDOR (Insecure Direct Object Reference) vulnerability allows unauthorized users to manipulate object references to access private data.
Yes, CVE-2024-4750 can be exploited by authenticated users who can manipulate the post IDs in their requests.