UnAuthenticated Privilege Escalation in WPCOM Member Plugin
CVE-2024-7493

9.8CRITICAL

Key Information:

Vendor
Whyun
Status
WPcom Member
Vendor
CVE Published:
6 September 2024

Summary

The WPCOM Member plugin for WordPress is susceptible to a privilege escalation flaw. This vulnerability is present in all versions up to and including 1.5.2.1. It arises from the plugin's mishandling of data during the registration process, specifically allowing unsanitized data to be passed to the wp_insert_user() function. Consequently, unauthenticated attackers can exploit this flaw to elevate their user roles to that of an administrator, thereby gaining unauthorized access to sensitive areas of the website and performing actions at an elevated privilege level.

Affected Version(s)

WPCOM Member * <= 1.5.2.1

References

CVSS V3.1

Score:
9.8
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Collectors

NVD DatabaseMitre Database

Credit

wesley
.