CVE-2024-9518
CVSS 3.1 Score 9.8 of 10 (high)
Details
Published Oct 10, 2024
Updated: Oct 15, 2024
CWE ID 269
Summary
CVE-2024-9518 is a privilege escalation vulnerability affecting the UserPlus plugin for WordPress. This issue, present in versions up to 2.0, stems from inadequate restrictions on the 'form_actions' and 'userplus_update_user_profile' functions. Consequently, unauthenticated attackers can manipulate the 'role' parameter during user registration, impersonating higher-level users and gaining unauthorized access to sensitive data or functionality. WordPress users are urged to update the UserPlus plugin to the latest version to mitigate this risk.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.