Privilege Escalation Vulnerability in Automatic
CVE-2024-27955

8.3HIGH

Key Information:

Vendor
WordPress
Status
Vendor
CVE Published:
17 May 2024

Summary

A Cross-Site Request Forgery (CSRF) vulnerability in the WP Automatic plugin developed by Automatic enables attackers to exploit the system for privilege escalation. This security flaw may allow unauthorized users to execute actions on behalf of legitimate users without their consent, thereby compromising the integrity of the web application. The vulnerability affects all versions of WP Automatic up to and including version 3.92.0. It is crucial for users of impacted versions to apply security measures and updates promptly to mitigate associated risks.

Affected Version(s)

Automatic <= 3.92.0

References

CVSS V3.1

Score:
8.3
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Rafie Muhammad (Patchstack)
.