Unauthorized Access to User Data in UserPlus Plugin for WordPress
CVE-2024-9520
5.4MEDIUM
Key Information:
- Vendor
Wordpress
- Vendor
- CVE Published:
- 10 October 2024
What is CVE-2024-9520?
The UserPlus plugin for WordPress is affected by a vulnerability that allows unauthorized access, alteration, and potential loss of data due to a missing capability check in several of its functions. This flaw impacts all versions up to and including 2.0, enabling authenticated attackers with subscriber-level permissions or higher to manipulate user meta data and plugin options. Such access may lead to serious implications for user security and data integrity within dependent WordPress sites.
Affected Version(s)
User registration & user profile – UserPlus * <= 2.0