Vulnerabilities > CVE-2024-9584 - Missing Authorization vulnerability in Webcraftplugins Image MAP PRO

047910
CVSS 5.4 - MEDIUM
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
LOW
Confidentiality impact
NONE
Integrity impact
LOW
Availability impact
LOW
network
low complexity
webcraftplugins
CWE-862

Summary

The Image Map Pro plugin for WordPress is vulnerable to unauthorized modification of data and loss of data due to a missing capability check on the AJAX functions in versions up to, and including, 6.0.20. This makes it possible for authenticated attackers with contributor-level privileges or above, to add, update or delete map projects.

Vulnerable Configurations

Part Description Count
Application
Webcraftplugins
1

Common Weakness Enumeration (CWE)