CVE-2024-3627

The Wheel of Life: Coaching and Assessment Tool for Life Coach plugin for WordPress is vulnerable to unauthorized modification and loss of data due to a missing capability check on several functions in the AjaxFunctions.php file in all versions up to, and including, 1.1.7. This makes it possible for authenticated attackers, with subscriber-level access and above, to delete arbitrary posts and modify settings.
Configurations

Configuration 1 (hide)

cpe:2.3:a:kraftplugins:wheel_of_life:*:*:*:*:*:wordpress:*:*

History

No history.

Information

Published : 2024-06-20 02:15

Updated : 2024-07-15 17:12


NVD link : CVE-2024-3627

Mitre link : CVE-2024-3627

CVE.ORG link : CVE-2024-3627


JSON object : View

Products Affected

kraftplugins

  • wheel_of_life
CWE
CWE-862

Missing Authorization