CVE-2024-6799: YITH Essential Kit for WooCommerce #1 <= 2.34.0 - Missing Authorization to Authenticated (Subscriber+) Limited Plugin Install, Activation, and Deactivation
The YITH Essential Kit for WooCommerce #1 plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'activatemodule', 'deactivatemodule', and 'installmodule' functions in all versions up to, and including, 2.34.0. This makes it possible for authenticated attackers, with Subscriber-level access and above, to install, activate, and deactivate plugins from a pre-defined list of available YITH plugins.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
wordpress/yith-essential-kit-for-woocommerceto a version that resolves this vulnerability.Fixed in 2.34.0Patch YITH Essential Kit for WooCommerce #1 <= 2.34.0 - Missing Authorization to Authenticated (Subscriber+) Limited Plugin Install, Activation, and Deactivation - Configuration
Ensure the plugin enforces a capability/authorization check on the 'activate_module', 'deactivate_module', and 'install_module' functions so Subscriber-level users cannot install, activate, or deactivate plugins from the pre-defined YITH list.
WordPress (plugin functions: activate_module, deactivate_module, install_module) capability check/authorization enforcement = required
Event History
Frequently Asked Questions
What is the severity of CVE-2024-6799?
CVE-2024-6799 is a medium severity vulnerability due to unauthorized modification of data.
How do I fix CVE-2024-6799?
To fix CVE-2024-6799, update the YITH Essential Kit for WooCommerce plugin to version 2.35.0 or later.
Who is affected by CVE-2024-6799?
CVE-2024-6799 affects all users of the YITH Essential Kit for WooCommerce plugin versions up to 2.34.0.
What functions are involved in CVE-2024-6799?
CVE-2024-6799 involves the 'activate_module', 'deactivate_module', and 'install_module' functions.
Is CVE-2024-6799 a local or remote vulnerability?
CVE-2024-6799 is a local vulnerability that can be exploited by authenticated users.