CVE-2024-11028

CVSS 3.1 Score 9.8 of 10 (high)

Details

Published Nov 13, 2024
CWE ID 288

Summary

CVE-2024-11028 is a vulnerability affecting the MultiManager WP plugin for WordPress, where versions up to and including 1.0.5 are impacted. This issue stems from the inappropriate handling of user-supplied input in the plugin's user impersonation feature. As a result, unauthenticated attackers can generate impersonation links to log in as any existing user, including administrators. The user impersonation feature was disabled in version 1.1.0 but was later re-enabled with a patch in version 1.1.2.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share