The ConvertPlus plugin for WordPress is vulnerable to unauthorized modification of data that can lead to a denial of service due to a missing capability check on the 'cp_dismiss_notice' AJAX endpoint in all versions up to, and including, 3.5.30. This makes it possible for authenticated attackers, with Subscriber-level access and above, to update option values to '1' on the WordPress site. This can be leveraged to update an option that would create an error on the site and deny service to legitimate users or be used to set some values to true such as registration.
Metrics
Affected Vendors & Products
References
History
Mon, 24 Feb 2025 16:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Convertplug
Convertplug convertplus |
|
CPEs | cpe:2.3:a:convertplug:convertplus:*:*:*:*:*:wordpress:*:* | |
Vendors & Products |
Convertplug
Convertplug convertplus |
Wed, 12 Feb 2025 16:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Wed, 12 Feb 2025 04:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | The ConvertPlus plugin for WordPress is vulnerable to unauthorized modification of data that can lead to a denial of service due to a missing capability check on the 'cp_dismiss_notice' AJAX endpoint in all versions up to, and including, 3.5.30. This makes it possible for authenticated attackers, with Subscriber-level access and above, to update option values to '1' on the WordPress site. This can be leveraged to update an option that would create an error on the site and deny service to legitimate users or be used to set some values to true such as registration. | |
Title | Popup Plugin For WordPress - ConvertPlus <= 3.5.30 - Missing Authorization to Authenticated (Subscriber+) Limited Options Update | |
Weaknesses | CWE-862 | |
References |
| |
Metrics |
cvssV3_1
|

Status: PUBLISHED
Assigner: Wordfence
Published: 2025-02-12T04:22:14.584Z
Updated: 2025-02-12T16:09:31.737Z
Reserved: 2025-01-29T22:38:26.146Z
Link: CVE-2024-13800

Updated: 2025-02-12T15:54:08.579Z

Status : Analyzed
Published: 2025-02-12T05:15:12.810
Modified: 2025-02-24T15:55:09.120
Link: CVE-2024-13800

No data.