Privilege Escalation Vulnerability in Automatic
CVE-2024-27955
8.3HIGH
What is CVE-2024-27955?
A Cross-Site Request Forgery (CSRF) vulnerability in the WP Automatic plugin developed by Automatic enables attackers to exploit the system for privilege escalation. This security flaw may allow unauthorized users to execute actions on behalf of legitimate users without their consent, thereby compromising the integrity of the web application. The vulnerability affects all versions of WP Automatic up to and including version 3.92.0. It is crucial for users of impacted versions to apply security measures and updates promptly to mitigate associated risks.
Affected Version(s)
Automatic <= 3.92.0