Back to overview

CVE-2024-2086

CRITICAL
10.0
CVSS 3.1
Description
The Integrate Google Drive – Browse, Upload, Download, Embed, Play, Share, Gallery, and Manage Your Google Drive Files Into Your WordPress Site plugin for WordPress is vulnerable to unauthorized access of data, modification of data, and loss of data due to a missing capability check on multiple AJAX in all versions up to, and including, 1.3.8. This makes it possible for authenticated attackers to modify plugin settings as well as allowing full read/write/delete access to the Google Drive associated with the plugin.

Metadata

CVE ID
CVE-2024-2086
State
PUBLISHED
Assigner
Wordfence
Reserved
2024-03-01 14:57 UTC
Published
2024-03-30 04:31 UTC
Last updated
2026-04-08 17:12 UTC
Primary CWE
CWE-862
CWE-862 Missing Authorization
Vendor / Product
princeahmed / File Manager for Google Drive – Integrate Google Drive
Sources
cve.org  ·  NVD

Severity & Metrics

10.0 CRITICAL CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:L
SSVC — CISA Coordinator
Exploitation
none
Automatable
yes
Tech. Impact
total
Affected products (1)
VendorProductPlatformVersions
princeahmed File Manager for Google Drive – Integrate Google Drive 0 ≤ 1.3.8
Weakness (CWE)
CWESourceDescription
CWE-862 cna CWE-862 Missing Authorization
CVSS scores (1)
ScoreSeverityVersionSourceVector
10.0 CRITICAL 3.1 cna CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:L
Back to overview