Privilege Escalation Vulnerability in Automatic
CVE-2024-27955
8.3HIGH
Summary
A Cross-Site Request Forgery (CSRF) vulnerability in the WP Automatic plugin developed by Automatic enables attackers to exploit the system for privilege escalation. This security flaw may allow unauthorized users to execute actions on behalf of legitimate users without their consent, thereby compromising the integrity of the web application. The vulnerability affects all versions of WP Automatic up to and including version 3.92.0. It is crucial for users of impacted versions to apply security measures and updates promptly to mitigate associated risks.
Affected Version(s)
Automatic <= 3.92.0
References
CVSS V3.1
Score:
8.3
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
Required
Scope:
Changed
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Rafie Muhammad (Patchstack)