CVE-2024-9265
CVSS 3.1 Score 9.8 of 10 (high)
Details
Summary
CVE-2024-9265 is a privilege escalation vulnerability affecting the Echo RSS Feed Post Generator plugin for WordPress. In all versions up to 5.4.6, the plugin fails to adequately restrict roles during registration, enabling unauthenticated attackers to register as administrators through the echo_check_post_header_sent() function. This issue poses a significant security risk, as administrators have unrestricted access to the WordPress site, potentially leading to data theft, unauthorized modifications, or further exploitation. Users are advised to update the plugin to the latest version or consider disabling it as a temporary measure until a patch is released.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.