CVE-2024-9522
CVSS 3.1 Score 8.8 of 10 (high)
Details
Published Oct 10, 2024
Updated: Oct 15, 2024
CWE ID 306
CWE ID 288
Summary
CVE-2024-9522 is a new vulnerability affecting the WP Users Masquerade plugin for WordPress. This issue allows authenticated attackers, with subscriber-level permissions and above, to bypass authentication and log in as any existing user on the site, including administrators. The root cause is incorrect authentication and capability checking in the 'ajax_masq_login' function, making it necessary for WordPress users to update the plugin to the latest version to mitigate this risk.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.