Blog

"Prevention is cheaper than a breach"

Live Vulnerability Intelligence

Threat Database

Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.

Total2
Critical0
High1
Medium0
Reset
Showing 1-2 of 2 records
Threat Entry Updated 2024-10-02

CVE-2024-8350 - Uncanny Groups For Learndash Plugin

The Uncanny Groups for LearnDash plugin for WordPress is vulnerable to user group add due to a missing capability check on the /wp-json/ulgm_management/v1/add_user/ REST API endpoint in all versions up to, and including, 6.1.0.1. This makes it possible for authenticated attackers, with group leader-level access and above, to add users to their group which ultimately allows them to leverage CVE-2024-8349 and gain admin access to the site.

PLUGIN Uncanny Groups For Learndash

CVE-2024-8350

LOW CVSS 2.7 2024-09-25
Threat Entry Updated 2024-10-02

CVE-2024-8349 - Uncanny Groups For Learndash Plugin

The Uncanny Groups for LearnDash plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including, 6.1.0.1. This is due to the plugin not properly restricting what users a group leader can edit. This makes it possible for authenticated attackers, with group leader-level access and above, to change admin account email addresses which can subsequently lead to admin account access.

PLUGIN Uncanny Groups For Learndash

CVE-2024-8349

HIGH CVSS 7.2 2024-09-25
Scroll to top