CVE-2024-9518
CVSS 3.1 Score 9.8 of 10 (high)
Details
Summary
CVE-2024-9518 identifies a critical vulnerability in the UserPlus plugin for WordPress, affecting versions up to and including 2.0, which allows unauthenticated attackers to escalate privileges by manipulating the 'role' parameter during user registration. The vulnerability stems from insufficient restrictions on the 'form_actions' and 'userplus_update_user_profile' functions. Organizations using this plugin are at risk of unauthorized access, leading to potential integrity and confidentiality breaches, with a CVSS base score of 9.8 indicating high severity. To remediate this issue, users should update the UserPlus plugin to a patched version that addresses these security flaws. The vulnerability's low attack complexity means it can be exploited easily over a network without requiring user interaction.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.