CVE-2024-8199: Reviews Feed – Add Testimonials and Customer Reviews From Google Reviews, Yelp, TripAdvisor, and More <= 1.1.2 - Missing Authorization to Authenticated (Subscriber+) Limited Settings Update
The Reviews Feed – Add Testimonials and Customer Reviews From Google Reviews, Yelp, TripAdvisor, and More plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'updateapikey' function in all versions up to, and including, 1.1.2. This makes it possible for authenticated attackers, with Subscriber-level access and above, to update API Key options.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2024-8199?
CVE-2024-8199 has a medium severity level due to the risk of unauthorized data modifications.
How do I fix CVE-2024-8199?
To fix CVE-2024-8199, update the Reviews Feed plugin to the latest version that includes the necessary capability checks.
Which versions of the Reviews Feed plugin are affected by CVE-2024-8199?
CVE-2024-8199 affects all versions of the Reviews Feed plugin for WordPress up to and including version 1.2.0.
What type of vulnerability is CVE-2024-8199?
CVE-2024-8199 is a data modification vulnerability due to a missing capability check.
Who can exploit CVE-2024-8199?
CVE-2024-8199 can be exploited by any authenticated user who can interact with the plugin's functionality.