plugin

Rover Idx Vulnerabilities

2 known security issues reported for the Rover Idx WordPress plugin. Most recent disclosed Oct 21, 2024.

1 high 1 medium

Running Rover Idx on your site? Check whether your installed version is affected.

Scan your site free

Rover IDX <= 3.0.0.2905 - Authenticated (Subscriber+) Authentication Bypass to Administrator

high

The Rover IDX plugin for WordPress is vulnerable to Authentication Bypass in versions up to, and including, 3.0.0.2905. This is due to insufficient validation and capability check on the 'rover_idx_refresh_social_callback' function. This makes it possible for authenticated attackers, with subscriber-level permissions a...

CVSS:
8.8
Affected:
up to 3.0.0.2905
Fixed in:
3.0.0.2906
Disclosed:
Oct 21, 2024

CVE-2024-10002 on NVD →

Rover IDX <= 3.0.0.2903 - Authenticated (Subscriber+) Missing Authorization via Multiple Functions

medium

The Rover IDX plugin for WordPress is vulnerable to unauthorized access, modification, and loss of data due to a missing capability check on multiple functions in all versions up to, and including, 3.0.0.2903. This makes it possible for authenticated attackers, with subscriber-level access and above, to add, modify, or...

CVSS:
6.3
Affected:
up to 3.0.0.2903
Fixed in:
3.0.0.2905
Disclosed:
Oct 21, 2024

CVE-2024-10003 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database