CVE-2024-8349: Uncanny Groups for LearnDash <= 6.1.0.1 - Authenticated (Group Leader+) Privilege Escalation
The Uncanny Groups for LearnDash plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including, 6.1.0.1. This is due to the plugin not properly restricting what users a group leader can edit. This makes it possible for authenticated attackers, with group leader-level access and above, to change admin account email addresses which can subsequently lead to admin account access.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-8349?
CVE-2024-8349 has a moderate severity due to its potential for privilege escalation.
How do I fix CVE-2024-8349?
To fix CVE-2024-8349, update the Uncanny Groups for LearnDash plugin to version 6.1.1 or later.
Who is affected by CVE-2024-8349?
CVE-2024-8349 affects all versions of the Uncanny Groups for LearnDash plugin up to and including 6.1.0.1 when used in WordPress.
What type of vulnerability is CVE-2024-8349?
CVE-2024-8349 is a privilege escalation vulnerability that allows unauthorized modifications by group leaders.
Can authenticated users exploit CVE-2024-8349?
Yes, authenticated users with group leader roles can exploit CVE-2024-8349 to edit other users.