CVE-2024-2505

The GamiPress WordPress plugin before 6.8.9's access control mechanism fails to properly restrict access to its settings, permitting Authors to manipulate requests and extend access to lower privileged users, like Subscribers, despite initial settings prohibiting such access. This vulnerability resembles broken access control, enabling unauthorized users to modify critical GamiPress WordPress plugin before 6.8.9 configurations.
Configurations

Configuration 1 (hide)

cpe:2.3:a:gamipress:gamipress:*:*:*:*:*:wordpress:*:*

History

08 May 2025, 18:24

Type Values Removed Values Added
First Time Gamipress
Gamipress gamipress
CPE cpe:2.3:a:gamipress:gamipress:*:*:*:*:*:wordpress:*:*
CWE NVD-CWE-noinfo
References () https://wpscan.com/vulnerability/9b3d6148-ecee-4e59-84a4-3b3e9898473b/ - () https://wpscan.com/vulnerability/9b3d6148-ecee-4e59-84a4-3b3e9898473b/ - Exploit, Third Party Advisory

21 Nov 2024, 09:09

Type Values Removed Values Added
References () https://wpscan.com/vulnerability/9b3d6148-ecee-4e59-84a4-3b3e9898473b/ - () https://wpscan.com/vulnerability/9b3d6148-ecee-4e59-84a4-3b3e9898473b/ -

03 Jul 2024, 01:53

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 8.1
Summary
  • (es) El mecanismo de control de acceso del complemento GamiPress WordPress anterior a 6.8.9 no restringe adecuadamente el acceso a su configuración, lo que permite a los autores manipular solicitudes y extender el acceso a usuarios con privilegios más bajos, como suscriptores, a pesar de que la configuración inicial prohíbe dicho acceso. Esta vulnerabilidad se asemeja a un control de acceso roto, lo que permite a usuarios no autorizados modificar el complemento crítico de GamiPress WordPress antes de las configuraciones 6.8.9.

29 Apr 2024, 06:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-04-29 06:15

Updated : 2025-05-08 18:24


NVD link : CVE-2024-2505

Mitre link : CVE-2024-2505

CVE.ORG link : CVE-2024-2505


JSON object : View

Products Affected

gamipress

  • gamipress