CVE-2024-9860: Bridge Core <= 3.3 - Missing Authorization to Authenticated (Subscriber+) Demo Import
The Bridge Core plugin for WordPress is vulnerable to unauthorized modification of data or loss of data due to a missing capability check on the 'importaction' and 'installpluginperdemo' functions in versions up to, and including, 3.3. This makes it possible for authenticated attackers with subscriber-level permissions or above, to delete or change plugin settings, import demo data, and install limited plugins.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-9860?
CVE-2024-9860 has been classified as a critical vulnerability due to the potential for unauthorized data modification or loss.
How do I fix CVE-2024-9860?
To fix CVE-2024-9860, update the Bridge Core plugin to version 3.4 or later, which addresses the missing capability checks.
Who is affected by CVE-2024-9860?
CVE-2024-9860 affects users of the Bridge Core plugin for WordPress versions up to and including 3.3.
What types of attacks can CVE-2024-9860 facilitate?
CVE-2024-9860 can facilitate unauthorized actions by authenticated attackers, leading to data corruption or manipulation.
Is there a workaround for CVE-2024-9860?
There are no effective workarounds for CVE-2024-9860, so it is highly recommended to update to the patched version.