UnAuthenticated Privilege Escalation in WPCOM Member Plugin
CVE-2024-7493
What is CVE-2024-7493?
The WPCOM Member plugin for WordPress is susceptible to a privilege escalation flaw. This vulnerability is present in all versions up to and including 1.5.2.1. It arises from the plugin's mishandling of data during the registration process, specifically allowing unsanitized data to be passed to the wp_insert_user() function. Consequently, unauthenticated attackers can exploit this flaw to elevate their user roles to that of an administrator, thereby gaining unauthorized access to sensitive areas of the website and performing actions at an elevated privilege level.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
WPCOM Member * <= 1.5.2.1
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved