CVE-2024-9067: Youzify – BuddyPress Community, User Profile, Social Network & Membership Plugin for WordPress <= 1.3.0 - Missing Authorization to Arbitrary (Subscriber+) Attachment Deletion
The Youzify – BuddyPress Community, User Profile, Social Network & Membership Plugin for WordPress plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'deleteattachment' function in all versions up to, and including, 1.3.0. This makes it possible for authenticated attackers, with Subscriber-level access and above, to delete arbitrary attachments.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-9067?
CVE-2024-9067 has a severity rating that allows unauthorized data modification, making it a significant security risk.
How do I fix CVE-2024-9067?
To resolve CVE-2024-9067, update the Youzify plugin to version 1.3.1 or later.
What does CVE-2024-9067 affect?
CVE-2024-9067 affects all versions of the Youzify plugin for WordPress up to and including 1.3.0.
What type of vulnerability is CVE-2024-9067?
CVE-2024-9067 is an unauthorized modification of data due to a missing capability check.
Who is affected by CVE-2024-9067?
Users of the Youzify plugin for WordPress who have not updated beyond version 1.3.0 are at risk due to CVE-2024-9067.