Donations < 1.4 - Unauthenticated Arbitrary Options Change
Strategic Overview
- Status
- Patched in 1.4
- Affected Plugin
- Donations
- Affected Version
< 1.4- CVSS
- 8.2High
- Weakness type
- CWE-269 · Improper Privilege Management
- CVE
CVE-2019-15772
At a glance
CVE-2019-15772 is a high-severity Improper Privilege Management vulnerability in the Donations WordPress plugin, affecting versions < 1.4. It carries a CVSS score of 8.2 (reachable over the network; low attack complexity; high integrity impact). Exploitation requires no authentication. The issue is fixed in version 1.4; sites on affected versions should update now. Disclosed August 2019, reported by Jerome Bruandet.
Vulnerability Overview
The Donations plugin before 1.4 for WordPress has a nopriv_ AJAX action that allows modification of the siteurl setting.
Technical Analysis
The vector marks this flaw as remotely reachable over the network, with low attack complexity — no special timing or configuration is needed, and no privileges on the target site. A successful exploit has high impact on integrity.
CWE-269: Improper Privilege Management
Reaching this weakness in Donations < 1.4 takes no account at all. Improper privilege management means the code lets an account end up with capabilities its role should not have.
It converts a low-privileged account into an administrative one, which makes every other restriction on the site irrelevant. For Donations the fix is 1.4: builds < 1.4 are affected, anything from 1.4 onward is not.
Remediation
Update to version 1.4, or a newer patched version
How does WordSec protect against this?
This one needs no account at all, which puts it outside what login hardening can reach; WordSec's login security narrows the account-level paths around it, and the firewall is what inspects the request itself. None of that substitutes for the fix: Donations 1.4 closes this, and updating the plugin is the step that ends it.
- Login Security
- Alerts
External References
Related records
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C