CVE-2024-8350: Uncanny Groups for LearnDash <= 6.1.0.1 - Missing Authorization to Authenticated (Group Leader+) User Group Add
The Uncanny Groups for LearnDash plugin for WordPress is vulnerable to user group add due to a missing capability check on the /wp-json/ulgmmanagement/v1/adduser/ REST API endpoint in all versions up to, and including, 6.1.0.1. This makes it possible for authenticated attackers, with group leader-level access and above, to add users to their group which ultimately allows them to leverage CVE-2024-8349 and gain admin access to the site.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-8350?
CVE-2024-8350 is classified as a high severity vulnerability due to the potential for authenticated attackers to exploit it.
How do I fix CVE-2024-8350?
To fix CVE-2024-8350, update the Uncanny Groups for LearnDash plugin to version 6.1.1 or later.
Who is affected by CVE-2024-8350?
All versions of the Uncanny Groups for LearnDash plugin for WordPress up to and including version 6.1.0.1 are affected by CVE-2024-8350.
What type of vulnerability is CVE-2024-8350?
CVE-2024-8350 is a REST API vulnerability caused by a missing capability check.
Can CVE-2024-8350 lead to unauthorized access?
Yes, CVE-2024-8350 can allow authenticated attackers to add users to groups without proper permissions.