CVE-2024-50476 CRITICAL

CVE-2024-50476: WordPress GRÜN spendino Spendenformular plugin <= 1.0.1 - Arbitrary Option Update to Privilege Escalation vulnerability

Vendor Grün Software Group Gmbh
Product GRÜN spendino Spendenformular
Weakness CWE-862 · Missing authorization
Published October 29, 2024
Last update April 28, 2026

CVSS base score

9.8/10
Attack vector Network
Attack complexity Low
Privileges required None
User interaction None
Confidentiality High
Integrity High

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

What the vulnerability does

01Description

Missing Authorization vulnerability in GRÜN Software Group GmbH GRÜN spendino Spendenformular spendino allows Privilege Escalation.This issue affects GRÜN spendino Spendenformular: from n/a through <= 1.0.1.

Explanation of Vulnerability in Simple Terms

02Summary

GRÜN spendino Spendenformular versions 1.0.1 and earlier lack authorization checks, allowing unauthenticated attackers to read, modify, or delete donation data without restriction. The vulnerability affects all versions from release through 1.0.1. No authentication or user interaction is required to exploit this flaw.

What an attacker can do

03Attacker Capabilities

Read, modify, or delete donation records and sensitive data without any authentication.

Potential impact on your site

04Site Impact

Attackers can access, alter, or destroy all donation data and records stored in the form.

Conditions required to exploit

05Prerequisites

Network access to the donation form; no authentication or user interaction required.

Key dates

06Disclosure timeline

October 29, 2024 CVE published
April 28, 2026 Record updated

Related vulnerabilities

08Related CVE