CVE-2024-2019 Information

Description

The WP-DB-Table-Editor plugin for WordPress is vulnerable to unauthorized access of data modification of data and loss of data due to lack of a default capability requirement on the ‘dbte_render’ function in all versions up to and including 1.8.4. This makes it possible for authenticated attackers with contributor access and above to modify database tables that the theme has been configured to use the plugin to edit.

CVSS Vector

CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H

Reference

https://www.wordfence.com/threat-intel/vulnerabilities/id/2d044e0a-a956-4319-985d-6a9a276daf49?source=cve https://plugins.trac.wordpress.org/browser/wp-db-table-editor/trunk/db-table-editor.php

Attack Complexity

HIGH

Privileges Required

LOW

User Interaction Required

LOW

Scope

NONE

Confidentiality Impact

UNCHANGED

Integrity Impact

HIGH

Availability Impact

HIGH

Base Score

HIGH

Base Severity

7.5

Share on: