CVE-2024-9522

CVSS 3.1 Score 8.8 of 10 (high)

Details

Published Oct 10, 2024
Updated: Oct 15, 2024
CWE ID 306
CWE ID 288

Summary

CVE-2024-9522 is a new vulnerability affecting the WP Users Masquerade plugin for WordPress. This issue allows authenticated attackers, with subscriber-level permissions and above, to bypass authentication and log in as any existing user on the site, including administrators. The root cause is incorrect authentication and capability checking in the 'ajax_masq_login' function, making it necessary for WordPress users to update the plugin to the latest version to mitigate this risk.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share