CVE-2024-9518

CVSS 3.1 Score 9.8 of 10 (high)

Details

Published Oct 10, 2024
CWE ID 269

Summary

CVE-2024-9518 identifies a critical vulnerability in the UserPlus plugin for WordPress, affecting versions up to and including 2.0, which allows unauthenticated attackers to escalate privileges by manipulating the 'role' parameter during user registration. The vulnerability stems from insufficient restrictions on the 'form_actions' and 'userplus_update_user_profile' functions. Organizations using this plugin are at risk of unauthorized access, leading to potential integrity and confidentiality breaches, with a CVSS base score of 9.8 indicating high severity. To remediate this issue, users should update the UserPlus plugin to a patched version that addresses these security flaws. The vulnerability's low attack complexity means it can be exploited easily over a network without requiring user interaction.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share