CVE-2024-8485

CVSS 3.1 Score 9.8 of 10 (high)

Details

Published Sep 25, 2024
Updated: Oct 2, 2024
CWE ID 639

Summary

CVE-2024-8485 is a privilege escalation vulnerability affecting the REST API TO MiniProgram plugin for WordPress. Unauthenticated attackers can exploit this issue, present in versions up to 4.7.1, by manipulating the 'openid' user-controlled key used in the updateUserInfo() function. The missing validation on this key allows attackers to update arbitrary user accounts, including their email addresses to @weixin.com email addresses. This email address change can then be used to reset the user's password, including that of administrator accounts. The vulnerability poses a significant risk to WordPress sites using the REST API TO MiniProgram plugin and can lead to unauthorized account takeover.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share

Affected Products

  • Rest Api To Miniprogram Plugin

Affected Vendors

  • WordPress