Patreon WordPress <= 1.9.0 - Protection Mechanism Bypass

2024-06-28 00:00
MCboyIR

Strategic Overview

Status
Patched in 1.9.1
Affected PluginPatreon WordPress
Affected Version<= 1.9.0
CVSS5.3Medium
CVECVE-2024-37430
View all Patreon WordPress vulnerabilities

Vulnerability Overview

The Patreon WordPress plugin for WordPress is vulnerable to protection mechanism bypass in all versions up to, and including, 1.9.0. This is due to plugin allowing a bypass when a specific header was supplied. This makes it possible for unauthenticated attackers to bypass image locking protections.

Technical Analysis

REMEDIATION: Update to version 1.9.1, or a newer patched version --- IDENTIFIER: CWE-693 (Protection Mechanism Failure) The product does not use or incorrectly uses a protection mechanism that provides sufficient defense against directed attacks against the product.

External References

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C