CVE-2024-5489: Wbcom Designs - Custom Font Uploader <= 2.3.4 - Missing Authorization to Font Deletion
The Wbcom Designs – Custom Font Uploader plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check on the 'cfudeletecustomfont' function in all versions up to, and including, 2.3.4. This makes it possible for authenticated attackers, with Subscriber-level access and above, to delete any custom font.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
wordpress/Wbcom Designs – Custom Font Uploaderto a version that resolves this vulnerability.Fixed in 2.3.4
Event History
Frequently Asked Questions
What is the severity of CVE-2024-5489?
CVE-2024-5489 is considered a high severity vulnerability due to its impact on data integrity for WordPress sites using the Wbcom Designs – Custom Font Uploader plugin.
How do I fix CVE-2024-5489?
To fix CVE-2024-5489, update the Wbcom Designs – Custom Font Uploader plugin to version 2.4.0 or later.
Who is affected by CVE-2024-5489?
Any WordPress site using Wbcom Designs – Custom Font Uploader plugin versions up to and including 2.3.4 is affected by CVE-2024-5489.
What types of attacks can be executed due to CVE-2024-5489?
CVE-2024-5489 can allow authenticated attackers to delete custom fonts without proper authorization, leading to potential data loss.
Is authentication required to exploit CVE-2024-5489?
Yes, exploitation of CVE-2024-5489 requires an authenticated user with sufficient privileges to invoke the vulnerable function.