| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-50544 | The Friends plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on several REST API endpoints in all versions up to, and including, 3.2.1. This makes it possible for unauthenticated attackers to send arbitrary friend requests on behalf of another website, accept the friend request for the targeted website, and then communicate with the site as an accepted friend. |
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Wed, 08 Apr 2026 17:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
Sat, 12 Jul 2025 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
epss
|
epss
|
Fri, 06 Dec 2024 18:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Alex Kirk
Alex Kirk friends |
|
| CPEs | cpe:2.3:a:alex_kirk:friends:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Alex Kirk
Alex Kirk friends |
|
| Metrics |
ssvc
|
Fri, 06 Dec 2024 08:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The Friends plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on several REST API endpoints in all versions up to, and including, 3.2.1. This makes it possible for unauthenticated attackers to send arbitrary friend requests on behalf of another website, accept the friend request for the targeted website, and then communicate with the site as an accepted friend. | |
| Title | Friends <= 3.2.1 - Missing Authorization | |
| Weaknesses | CWE-862 | |
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: Wordfence
Published:
Updated: 2026-04-08T17:10:36.536Z
Reserved: 2024-12-02T15:04:16.202Z
Link: CVE-2024-12028
Updated: 2024-12-06T17:23:05.481Z
Status : Awaiting Analysis
Published: 2024-12-06T09:15:07.957
Modified: 2026-04-08T18:19:38.593
Link: CVE-2024-12028
No data.
OpenCVE Enrichment
No data.
EUVD