UnAuthenticated Privilege Escalation in WPCOM Member Plugin
CVE-2024-7493
9.8CRITICAL
Key Information:
- Vendor
- Whyun
- Status
- WPcom Member
- Vendor
- CVE Published:
- 6 September 2024
Summary
The WPCOM Member plugin for WordPress is susceptible to a privilege escalation flaw. This vulnerability is present in all versions up to and including 1.5.2.1. It arises from the plugin's mishandling of data during the registration process, specifically allowing unsanitized data to be passed to the wp_insert_user() function. Consequently, unauthenticated attackers can exploit this flaw to elevate their user roles to that of an administrator, thereby gaining unauthorized access to sensitive areas of the website and performing actions at an elevated privilege level.
Affected Version(s)
WPCOM Member * <= 1.5.2.1
References
CVSS V3.1
Score:
9.8
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
Collectors
NVD DatabaseMitre Database
Credit
wesley