GP Unique ID <= 1.5.5 - Unauthenticated Form Submission Unique ID Modification

2024-04-10 00:00
Karl Emil Nikka

Strategic Overview

Status
Patched in 1.5.6
Affected PluginGP Unique ID
Affected Version<= 1.5.5
CVSS5.3Medium
CVECVE-2024-0710
View all GP Unique ID vulnerabilities

Vulnerability Overview

The GP Unique ID plugin for WordPress is vulnerable to Unique ID Modification in all versions up to, and including, 1.5.5. This is due to insufficient input validation. This makes it possible for unauthenticated attackers to tamper with the generation of a unique ID on a form submission and replace the generated unique ID with a user-controlled one, leading to a loss of integrity in cases where the ID's uniqueness is relied upon in a security-specific context.

Technical Analysis

REMEDIATION: Update to version 1.5.6, or a newer patched version --- IDENTIFIER: CWE-20 (Improper Input Validation) The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.

External References

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C