Unauthenticated Attackers Can Escalate Privileges via UserPlus Plugin
CVE-2024-9518
9.8CRITICAL
Key Information:
- Vendor
Wordpress
- Vendor
- CVE Published:
- 10 October 2024
What is CVE-2024-9518?
The UserPlus plugin for WordPress suffers from a privilege escalation issue due to inadequate controls on the 'form_actions' and 'userplus_update_user_profile' functions. An unauthenticated attacker could manipulate the 'role' parameter during user registration, granting unauthorized access and potentially elevating their privileges within the WordPress environment. This vulnerability highlights the importance of proper validation and restriction mechanisms in user management functionalities.
Affected Version(s)
User registration & user profile – UserPlus * <= 2.0