GP Unique ID <= 1.5.5 - Unauthenticated Form Submission Unique ID Modification
Summary
| CVE | CVE-2024-0710 |
|---|---|
| State | PUBLISHED |
| Assigner | Wordfence |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2024-05-02 17:15:09 UTC |
| Updated | 2026-04-08 17:17:24 UTC |
| Description | The GP Unique ID plugin for WordPress is vulnerable to Unique ID Modification in all versions up to, and including, 1.5.5. This is due to insufficient input validation. This makes it possible for unauthenticated attackers to tamper with the generation of a unique ID on a form submission and replace the generated unique ID with a user-controlled one, leading to a loss of integrity in cases where the ID's uniqueness is relied upon in a security-specific context. |
Risk And Classification
Primary CVSS: v3.1 5.3 MEDIUM from [email protected]
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
Problem Types: CWE-20 | CWE-20 CWE-20 Improper Input Validation
| Version | Source | Type | Score | Severity | Vector |
|---|---|---|---|---|---|
| 3.1 | [email protected] | Secondary | 5.3 | MEDIUM | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N |
| 3.1 | CNA | DECLARED | 5.3 | MEDIUM | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N |
CVSS v3.1 Breakdown
Attack Vector
NetworkAttack Complexity
LowPrivileges Required
NoneUser Interaction
NoneScope
UnchangedConfidentiality
NoneIntegrity
LowAvailability
NoneCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
Vendor Declared Affected Products
| Source | Vendor | Product | Version | Platforms |
|---|---|---|---|---|
| CNA | Gravity Wiz | GP Unique ID | affected 1.5.5 semver | Not specified |
| ADP | Gravity Wiz | Gp Unique Id | affected 1.5.5 | Not specified |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| github.com/karlemilnikka/CVE-2024-0710/blob/main/README.md | af854a3a-2127-422b-91ae-364da2661108 | github.com | |
| www.wordfence.com/threat-intel/vulnerabilities/id/26db2d25-01b8-49c5-a4d6-28478... | af854a3a-2127-422b-91ae-364da2661108 | www.wordfence.com | |
| gravitywiz.com/documentation/gravity-forms-unique-id | af854a3a-2127-422b-91ae-364da2661108 | gravitywiz.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
Vendor Comments And Credit
Discovery Credit
CNA: Karl Emil Nikka (en)
Additional Advisory Data
| Source | Time | Event |
|---|---|---|
| CNA | 2024-01-13T00:00:00.000Z | Vendor Notified |
| CNA | 2024-04-10T00:00:00.000Z | Disclosed |
There are currently no legacy QID mappings associated with this CVE.