Rover IDX <= 3.0.0.2905 - Authenticated (Subscriber+) Authentication Bypass to Administrator

2024-10-21 00:00
István Márton

Strategic Overview

Status
Patched in 3.0.0.2906
Affected PluginRover IDX
Affected Version<= 3.0.0.2905
CVSS8.8High
CVECVE-2024-10002
View all Rover IDX vulnerabilities

Vulnerability Overview

The Rover IDX plugin for WordPress is vulnerable to Authentication Bypass in versions up to, and including, 3.0.0.2905. This is due to insufficient validation and capability check on the 'rover_idx_refresh_social_callback' function. This makes it possible for authenticated attackers, with subscriber-level permissions and above, to log in to administrator. The vulnerability is partially patched in version 3.0.0.2905 and fully patched in version 3.0.0.2906.

Technical Analysis

REMEDIATION: Update to version 3.0.0.2906, or a newer patched version --- IDENTIFIER: CWE-288 (Authentication Bypass Using an Alternate Path or Channel) The product requires authentication, but the product has an alternate path or channel that does not require authentication.

External References

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C