CVE-2024-5087
CVE-2024-5087: A WordPress plugin vulnerability allows unauthorized data modification. This affects the 'Minimal Coming Soon – Coming Soon Page' plugin up to version 2.38. Authenticated attackers with Subscriber-level access can edit the license key due to missing capability checks, potentially disabling crucial plugin features.
The vulnerability lies in the validate_ajax
, deactivate_ajax
, and save_ajax
functions, where proper authorization checks are absent. Although the CVSS score is 5.4, indicating medium severity, the SOCRadar Vulnerability Risk Score (SVRS) is 30, suggesting a lower immediate risk. This CVE is significant because it allows lower-privileged users to impact plugin functionality, potentially disrupting site features and requiring administrative intervention for remediation. Successful exploitation could lead to denial of service or unauthorized access depending on plugin configuration and installed features.
Description:
CVE-2024-5087 is a vulnerability in the Minimal Coming Soon – Coming Soon Page plugin for WordPress that allows authenticated attackers with Subscriber-level access and above to edit the license key, potentially disabling plugin features.
Key Insights:
- SVRS Score: 34 (Moderate)
- Exploit Status: No active exploits have been published.
- CISA Warnings: No warnings have been issued by CISA.
- In the Wild: The vulnerability is not currently being exploited in the wild.
Mitigation Strategies:
- Update the Minimal Coming Soon – Coming Soon Page plugin to version 2.39 or later.
- Restrict access to the plugin's settings to only authorized users.
- Regularly monitor the plugin for any suspicious activity.
- Implement a web application firewall (WAF) to block unauthorized access to the plugin's functions.
Additional Information:
If users have additional queries regarding this incident, they can use the 'Ask to Analyst' feature, contact SOCRadar directly, or open a support ticket for more information if necessary.
Indicators of Compromise
Exploits
News
Social Media
Affected Software
References
CWE Details
CVE Radar
Real-time CVE Intelligence & Vulnerability Management Platform
CVE Radar provides comprehensive vulnerability intelligence by monitoring CVE databases, security advisories, and threat feeds. Get instant updates on new vulnerabilities, exploit details, and mitigation strategies specific to your assets.