CVE-2024-11028
CVSS 3.1 Score 9.8 of 10 (high)
Details
Published Nov 13, 2024
CWE ID 288
Summary
CVE-2024-11028 is a vulnerability affecting the MultiManager WP plugin for WordPress, where versions up to and including 1.0.5 are impacted. This issue stems from the inappropriate handling of user-supplied input in the plugin's user impersonation feature. As a result, unauthenticated attackers can generate impersonation links to log in as any existing user, including administrators. The user impersonation feature was disabled in version 1.1.0 but was later re-enabled with a patch in version 1.1.2.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.