The HurryTimer – An Scarcity and Urgency Countdown Timer for WordPress & WooCommerce plugin for WordPress is vulnerable to unauthorized post publication due to a missing capability check on the activateCampaign() function in all versions up to, and including, 2.10.0. This makes it possible for authenticated attackers, with contributor-level access and above, to publish arbitrary posts like ones they have submitted for review, or a site administrator has in draft.
                
            Metrics
Affected Vendors & Products
References
        History
                    Thu, 24 Oct 2024 19:15:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| Metrics | 
        
        ssvc
         
  | 
Thu, 24 Oct 2024 07:45:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| Description | The HurryTimer – An Scarcity and Urgency Countdown Timer for WordPress & WooCommerce plugin for WordPress is vulnerable to unauthorized post publication due to a missing capability check on the activateCampaign() function in all versions up to, and including, 2.10.0. This makes it possible for authenticated attackers, with contributor-level access and above, to publish arbitrary posts like ones they have submitted for review, or a site administrator has in draft. | |
| Title | HurryTimer – An Scarcity and Urgency Countdown Timer for WordPress & WooCommerce <= 2.10.0 - Missing Authorization to Authenticated (Contributor+) Arbitrary Post Publication | |
| Weaknesses | CWE-862 | |
| References | 
         | |
| Metrics | 
        
        cvssV3_1
         
  | 
Status: PUBLISHED
Assigner: Wordfence
Published: 2024-10-24T07:35:56.502Z
Updated: 2024-10-24T18:40:47.563Z
Reserved: 2024-09-10T17:06:35.815Z
Link: CVE-2024-8667
Updated: 2024-10-24T18:40:44.367Z
Status : Awaiting Analysis
Published: 2024-10-24T08:15:02.430
Modified: 2024-10-25T12:56:07.750
Link: CVE-2024-8667
No data.