PT-2024-39165 · WordPress · The Hurrytimer

·

CVE-2024-8667

·

Published

2024-10-24

·

Updated

2024-10-25

CVSS v3.1

4.3

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions: The HurryTimer – An Scarcity and Urgency Countdown Timer for WordPress & WooCommerce plugin versions up to, and including, 2.10.0
Description: The issue allows authenticated attackers with contributor-level access and above to publish arbitrary posts, including ones they have submitted for review or a site administrator has in draft, due to a missing capability check on the activateCampaign() function.
Recommendations: For versions up to, and including, 2.10.0, update to a version that includes a fix for the missing capability check on the activateCampaign() function. As a temporary workaround, consider restricting access to the activateCampaign() function to prevent unauthorized post publication.

Fix

Missing Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2024-8667

Affected Products

The Hurrytimer