The MultiManager WP – Manage All Your WordPress Sites Easily plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and including, 1.0.5. This is due to the user impersonation feature inappropriately determining the current user via user-supplied input. This makes it possible for unauthenticated attackers to generate an impersonation link that will allow them to log in as any existing user, such as an administrator. NOTE: The user impersonation feature was disabled in version 1.1.0 and re-enabled with a patch in version 1.1.2.
History

Wed, 13 Nov 2024 15:15:00 +0000

Type Values Removed Values Added
First Time appeared Icdsoft
Icdsoft multimanager Wp Manage All Your Word Press Sites Easily
CPEs cpe:2.3:a:icdsoft:multimanager_wp_manage_all_your_word_press_sites_easily:*:*:*:*:*:*:*:*
Vendors & Products Icdsoft
Icdsoft multimanager Wp Manage All Your Word Press Sites Easily
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 13 Nov 2024 09:45:00 +0000

Type Values Removed Values Added
Description The MultiManager WP – Manage All Your WordPress Sites Easily plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and including, 1.0.5. This is due to the user impersonation feature inappropriately determining the current user via user-supplied input. This makes it possible for unauthenticated attackers to generate an impersonation link that will allow them to log in as any existing user, such as an administrator. NOTE: The user impersonation feature was disabled in version 1.1.0 and re-enabled with a patch in version 1.1.2.
Title MultiManager WP – Manage All Your WordPress Sites Easily <= 1.0.5 - Authentication Bypass via User Impersonation
Weaknesses CWE-288
References
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: Wordfence

Published: 2024-11-13T09:30:26.145Z

Updated: 2024-11-13T14:59:40.159Z

Reserved: 2024-11-08T16:48:44.283Z

Link: CVE-2024-11028

cve-icon Vulnrichment

Updated: 2024-11-13T14:59:32.896Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2024-11-13T10:15:04.237

Modified: 2024-11-13T17:01:16.850

Link: CVE-2024-11028

cve-icon Redhat

No data.