Gtbabel <= 6.6.8 - Unauthenticated Cookie Stealing

Strategic Overview

Status
Patched in 6.6.9
Affected PluginGtbabel
Affected Version<= 6.6.8
CVSS7.5High
CVECVE-2024-11638
View all Gtbabel vulnerabilities

Vulnerability Overview

The Gtbabel plugin for WordPress is vulnerable to cookie stealing in all versions up to, and including, 6.6.8. This is due to the plugin transmitting cookie data via a URL. This makes it possible for unauthenticated attackers to steal admin cookies which may make privilege escalation possible, if they can successfully trick in administrator into clicking a link.

Technical Analysis

REMEDIATION: Update to version 6.6.9, or a newer patched version --- IDENTIFIER: CWE-614 (Sensitive Cookie in HTTPS Session Without 'Secure' Attribute) The Secure attribute for sensitive cookies in HTTPS sessions is not set.

External References

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C