Friends <= 3.2.1 - Missing Authorization

2024-12-05 19:45
Colin Xu

Strategic Overview

Status
Patched in 3.2.2
Affected PluginFriends
Affected Version<= 3.2.1
CVSS5.3Medium
CVECVE-2024-12028
View all Friends vulnerabilities

Vulnerability Overview

The Friends plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on several REST API endpoints in all versions up to, and including, 3.2.1. This makes it possible for unauthenticated attackers to send arbitrary friend requests on behalf of another website, accept the friend request for the targeted website, and then communicate with the site as an accepted friend.

Technical Analysis

REMEDIATION: Update to version 3.2.2, or a newer patched version --- IDENTIFIER: CWE-862 (Missing Authorization) The product does not perform an authorization check when an actor attempts to access a resource or perform an action.

External References

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C