The ConvertKit – Email Newsletter, Email Marketing, Subscribers and Landing Pages plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the tag_subscriber function in all versions up to, and including, 2.4.9. This makes it possible for unauthenticated attackers to subscribe users to tags. Financial damages may occur to site owners if their API quota is exceeded.
References
Configurations
Configuration 1 (hide)
|
History
17 Jul 2024, 13:32
Type | Values Removed | Values Added |
---|---|---|
References | () https://plugins.trac.wordpress.org/changeset?sfp_email=&sfph_mail=&reponame=&new=3104932%40convertkit%2Ftrunk&old=3085997%40convertkit%2Ftrunk&sfp_email=&sfph_mail= - Product | |
References | () https://www.wordfence.com/threat-intel/vulnerabilities/id/79d828b8-aea2-4705-ae23-ac70133a6c3e?source=cve - Third Party Advisory | |
Summary |
|
|
First Time |
Convertkit
Convertkit convertkit - Email Marketing\, Email Newsletter And Landing Pages |
|
CWE | CWE-862 | |
CPE | cpe:2.3:a:convertkit:convertkit_-_email_marketing\,_email_newsletter_and_landing_pages:*:*:*:*:*:wordpress:*:* |
21 Jun 2024, 04:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2024-06-21 04:15
Updated : 2024-07-17 13:32
NVD link : CVE-2024-3961
Mitre link : CVE-2024-3961
CVE.ORG link : CVE-2024-3961
JSON object : View
Products Affected
convertkit
- convertkit_-_email_marketing\,_email_newsletter_and_landing_pages
CWE
CWE-862
Missing Authorization