Rover IDX <= 3.0.0.2905 - Authenticated (Subscriber+) Authentication Bypass to Administrator
high
The Rover IDX plugin for WordPress is vulnerable to Authentication Bypass in versions up to, and including, 3.0.0.2905. This is due to insufficient validation and capability check on the 'rover_idx_refresh_social_callback' function. This makes it possible for authenticated attackers, with subscriber-level permissions a...
- CVSS:
- 8.8
- Affected:
- up to 3.0.0.2905
- Fixed in:
- 3.0.0.2906
- Disclosed:
- Oct 21, 2024
CVE-2024-10002 on NVD →
Rover IDX <= 3.0.0.2903 - Authenticated (Subscriber+) Missing Authorization via Multiple Functions
medium
The Rover IDX plugin for WordPress is vulnerable to unauthorized access, modification, and loss of data due to a missing capability check on multiple functions in all versions up to, and including, 3.0.0.2903. This makes it possible for authenticated attackers, with subscriber-level access and above, to add, modify, or...
- CVSS:
- 6.3
- Affected:
- up to 3.0.0.2903
- Fixed in:
- 3.0.0.2905
- Disclosed:
- Oct 21, 2024
CVE-2024-10003 on NVD →
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database