CVE-2024-8350
Uncanny Groups for LearnDash <= 6.1.0.1 - Missing Authorization to Authenticated (Group Leader+) User Group Add
CVSS Score
2.7
EPSS Score
0.0%
EPSS Percentile
0th
The Uncanny Groups for LearnDash plugin for WordPress is vulnerable to user group add due to a missing capability check on the /wp-json/ulgm_management/v1/add_user/ REST API endpoint in all versions up to, and including, 6.1.0.1. This makes it possible for authenticated attackers, with group leader-level access and above, to add users to their group which ultimately allows them to leverage CVE-2024-8349 and gain admin access to the site.
| CWE | CWE-862 |
| Vendor | uncanny owl |
| Product | uncanny groups for learndash |
| Published | Sep 25, 2024 |
| Last Updated | Apr 8, 2026 |
Stay Ahead of the Next One
Get instant alerts for uncanny owl uncanny groups for learndash
Be the first to know when new low vulnerabilities affecting uncanny owl uncanny groups for learndash are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
CVSS v3 Breakdown
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:N Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability
Affected Versions
Uncanny Owl / Uncanny Groups for LearnDash
0 โค 6.1.0.1
References
Credits
Karl Emil Nikka