CVE · Medium

CVE-2024-9860 — Bridge Core [bridge-core] < 3.3.1

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2024-9860 Bridge Core [bridge-core] < 3.3.1 Missing Authorization Medium 6.5 < 3.3.1 3.3.1 2024-10-11

CVE-2024-9860

A security flaw exists in the Bridge Core plugin for WordPress, affecting versions prior to and including 3.3. The issue arises from a lack of permission checks on specific functions, enabling attackers with subscriber-level access or higher to manipulate plugin configurations, import demo content, and install restricted plugins. This vulnerability poses a risk of unauthorized data modification or loss.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.