Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-49072 | The WP-Recall – Registration, Profile, Commerce & More plugin for WordPress is vulnerable to privilege escalation/account takeover in all versions up to, and including, 16.26.8. This is due to to plugin not properly verifying a user's identity during new order creation. This makes it possible for unauthenticated attackers to supply any email through the user_email field and update the password for that user during new order creation. This requires the commerce addon to be enabled in order to exploit. |
Thu, 12 Sep 2024 13:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:2.3:a:plechevandrey:wp-recall:*:*:*:*:*:wordpress:*:* |
Fri, 06 Sep 2024 14:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Plechevandrey
Plechevandrey wp-recall |
|
| CPEs | cpe:2.3:a:plechevandrey:wp-recall:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Plechevandrey
Plechevandrey wp-recall |
|
| Metrics |
ssvc
|
Fri, 06 Sep 2024 07:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The WP-Recall – Registration, Profile, Commerce & More plugin for WordPress is vulnerable to privilege escalation/account takeover in all versions up to, and including, 16.26.8. This is due to to plugin not properly verifying a user's identity during new order creation. This makes it possible for unauthenticated attackers to supply any email through the user_email field and update the password for that user during new order creation. This requires the commerce addon to be enabled in order to exploit. | |
| Title | WP-Recall – Registration, Profile, Commerce & More <= 16.26.8 - Insecure Direct Object Reference to Unauthenticated Arbitrary Password Update | |
| Weaknesses | CWE-639 | |
| References |
|
|
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: Wordfence
Published:
Updated: 2026-04-08T17:06:37.337Z
Reserved: 2024-08-28T21:38:57.147Z
Link: CVE-2024-8292
Updated: 2024-09-06T13:31:45.633Z
Status : Analyzed
Published: 2024-09-06T07:15:03.010
Modified: 2024-09-12T12:37:18.380
Link: CVE-2024-8292
No data.
OpenCVE Enrichment
No data.
EUVD