CVE-2024-12821
CVSS 3.1 Score 8.8 of 10 (high)
Details
Published Jan 30, 2025
CWE ID 862
Summary
CVE-2024-12821: The Media Manager component in the UserPro plugin for WordPress, affecting versions up to 3.12.0, contains a vulnerability in the upm_upload_media() function. This issue allows authenticated attackers with Subscriber-level access or higher to bypass capability checks, enabling them to modify arbitrary options on vulnerable WordPress sites. Successful exploitation of this vulnerability can result in privilege escalation and the creation of administrative user accounts, providing attackers with full control over the site.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Share