The Passwords Manager plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'pms_save_setting' and 'post_new_pass' AJAX actions in all versions up to, and including, 1.4.8. This makes it possible for authenticated attackers, with Subscriber-level access and above, to update the plugins settings and add passwords.
Metrics
Affected Vendors & Products
References
History
Fri, 17 Jan 2025 22:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Hirewebxperts
Hirewebxperts passwords Manager |
|
Weaknesses | CWE-862 | |
CPEs | cpe:2.3:a:hirewebxperts:passwords_manager:*:*:*:*:*:wordpress:*:* | |
Vendors & Products |
Hirewebxperts
Hirewebxperts passwords Manager |
Thu, 16 Jan 2025 15:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Thu, 16 Jan 2025 09:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | The Passwords Manager plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'pms_save_setting' and 'post_new_pass' AJAX actions in all versions up to, and including, 1.4.8. This makes it possible for authenticated attackers, with Subscriber-level access and above, to update the plugins settings and add passwords. | |
Title | Passwords Manager <= 1.4.8 - Missing Authorization to Authenticated (Subscriber+) Add Password + Update Encryption Key | |
Weaknesses | CWE-89 | |
References |
|
|
Metrics |
cvssV3_1
|

Status: PUBLISHED
Assigner: Wordfence
Published: 2025-01-16T09:39:14.567Z
Updated: 2025-01-16T14:56:00.766Z
Reserved: 2024-12-13T14:15:33.798Z
Link: CVE-2024-12614

Updated: 2025-01-16T14:55:53.888Z

Status : Analyzed
Published: 2025-01-16T10:15:08.023
Modified: 2025-01-17T22:17:15.190
Link: CVE-2024-12614

No data.