The Enjoy Social Feed plugin for WordPress website WordPress plugin through 6.2.2 does not have authorisation when resetting its database, allowing any authenticated users, such as subscriber to perform such action
History

Fri, 14 Mar 2025 17:15:00 +0000

Type Values Removed Values Added
First Time appeared Mediabeta
Mediabeta enjoy Social Feed
CPEs cpe:2.3:a:mediabeta:enjoy_social_feed:*:*:*:*:*:*:*:*
Vendors & Products Mediabeta
Mediabeta enjoy Social Feed
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 27 Feb 2025 04:00:00 +0000

Type Values Removed Values Added
First Time appeared Mediabetaprojects
Mediabetaprojects enjoy Social Feed
Weaknesses CWE-862
CPEs cpe:2.3:a:mediabetaprojects:enjoy_social_feed:*:*:*:*:*:wordpress:*:*
Vendors & Products Mediabetaprojects
Mediabetaprojects enjoy Social Feed
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: WPScan

Published: 2024-03-18T19:05:41.368Z

Updated: 2025-03-14T16:20:28.257Z

Reserved: 2024-01-22T10:32:40.148Z

Link: CVE-2024-0780

cve-icon Vulnrichment

Updated: 2024-08-01T18:18:18.158Z

cve-icon NVD

Status : Modified

Published: 2024-03-18T19:15:06.437

Modified: 2025-03-14T17:15:40.607

Link: CVE-2024-0780

cve-icon Redhat

No data.