The PowerPack Pro for Elementor plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including, 2.10.17. This is due to the plugin not restricting low privileged users from setting a default role for a registration form. This makes it possible for authenticated attackers, with contributor-level access and above, to create a registration form with administrator set as the default role and then register as an administrator.
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: Wordfence

Published: 2024-06-08T04:32:36.859Z

Updated: 2024-08-01T20:20:00.472Z

Reserved: 2024-04-11T18:49:31.263Z

Link: CVE-2024-3668

cve-icon Vulnrichment

Updated: 2024-08-01T20:20:00.472Z

cve-icon NVD

Status : Analyzed

Published: 2024-06-08T05:15:40.040

Modified: 2024-07-23T19:39:25.253

Link: CVE-2024-3668

cve-icon Redhat

No data.