The WP Crowdfunding plugin for WordPress is vulnerable to unauthorized plugin installation due to a missing capability check on the install_woocommerce_plugin() function action in all versions up to, and including, 2.1.12. This makes it possible for authenticated attackers, with Subscriber-level access and above, to install WooCommerce. This has a limited impact on most sites because WooCommerce is a requirement.
History

Tue, 11 Feb 2025 14:45:00 +0000

Type Values Removed Values Added
First Time appeared Themeum
Themeum wp Crowdfunding
CPEs cpe:2.3:a:themeum:wp_crowdfunding:*:*:*:*:*:wordpress:*:*
Vendors & Products Themeum
Themeum wp Crowdfunding

Mon, 16 Dec 2024 20:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 13 Dec 2024 08:45:00 +0000

Type Values Removed Values Added
Description The WP Crowdfunding plugin for WordPress is vulnerable to unauthorized plugin installation due to a missing capability check on the install_woocommerce_plugin() function action in all versions up to, and including, 2.1.12. This makes it possible for authenticated attackers, with Subscriber-level access and above, to install WooCommerce. This has a limited impact on most sites because WooCommerce is a requirement.
Title WP Crowdfunding <= 2.1.12 - Missing Authorization to Authenticated (Subscriber+) WooCommerce Installation
Weaknesses CWE-862
References
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: Wordfence

Published:

Updated: 2024-12-16T20:07:27.042Z

Reserved: 2024-11-27T17:02:30.059Z

Link: CVE-2024-11911

cve-icon Vulnrichment

Updated: 2024-12-16T19:39:57.439Z

cve-icon NVD

Status : Analyzed

Published: 2024-12-13T09:15:07.083

Modified: 2025-02-11T14:21:42.667

Link: CVE-2024-11911

cve-icon Redhat

No data.