CVE-2024-9518

CVSS 3.1 Score 9.8 of 10 (high)

Details

Published Oct 10, 2024
Updated: Oct 15, 2024
CWE ID 269

Summary

CVE-2024-9518 is a privilege escalation vulnerability affecting the UserPlus plugin for WordPress. This issue, present in versions up to 2.0, stems from inadequate restrictions on the 'form_actions' and 'userplus_update_user_profile' functions. Consequently, unauthenticated attackers can manipulate the 'role' parameter during user registration, impersonating higher-level users and gaining unauthorized access to sensitive data or functionality. WordPress users are urged to update the UserPlus plugin to the latest version to mitigate this risk.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share