Patreon WordPress <= 1.9.0 - Protection Mechanism Bypass
2024-06-28 00:00
MCboyIRStrategic Overview
StatusPatched in 1.9.1
Affected PluginPatreon WordPress
Affected Version
<= 1.9.0CVSS5.3Medium
CVE
CVE-2024-37430Vulnerability Overview
The Patreon WordPress plugin for WordPress is vulnerable to protection mechanism bypass in all versions up to, and including, 1.9.0. This is due to plugin allowing a bypass when a specific header was supplied. This makes it possible for unauthenticated attackers to bypass image locking protections.
Technical Analysis
REMEDIATION: Update to version 1.9.1, or a newer patched version --- IDENTIFIER: CWE-693 (Protection Mechanism Failure) The product does not use or incorrectly uses a protection mechanism that provides sufficient defense against directed attacks against the product.
External References
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C