The Login with phone number plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including, 1.7.49. This is due to a lack of validation and missing capability check on user-supplied data in the 'lwp_update_password_action' function. This makes it possible for authenticated attackers, with Subscriber-level access and above, to update their role to any other role, including Administrator. The vulnerability was partially patched in version 1.7.40. The login with phone number pro plugin was required to exploit the vulnerability in versions 1.7.40 - 1.7.49.
Metrics
Affected Vendors & Products
References
History
Fri, 27 Sep 2024 14:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Idehweb
Idehweb login With Phone Number |
|
Weaknesses | NVD-CWE-noinfo | |
CPEs | cpe:2.3:a:idehweb:login_with_phone_number:*:*:*:*:*:wordpress:*:* | |
Vendors & Products |
Idehweb
Idehweb login With Phone Number |
Tue, 17 Sep 2024 02:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Hamid-alinia-idehweb
Hamid-alinia-idehweb login With Phone Number |
|
CPEs | cpe:2.3:a:hamid-alinia-idehweb:login_with_phone_number:*:*:*:*:*:*:*:* | |
Vendors & Products |
Hamid-alinia-idehweb
Hamid-alinia-idehweb login With Phone Number |
|
Metrics |
ssvc
|
Sat, 14 Sep 2024 12:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | The Login with phone number plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including, 1.7.49. This is due to a lack of validation and missing capability check on user-supplied data in the 'lwp_update_password_action' function. This makes it possible for authenticated attackers, with Subscriber-level access and above, to update their role to any other role, including Administrator. The vulnerability was partially patched in version 1.7.40. The login with phone number pro plugin was required to exploit the vulnerability in versions 1.7.40 - 1.7.49. | |
Title | Login with phone number <= 1.7.49 - Authenticated (Subscriber+) Authorization Bypass to Privilege Escalation | |
Weaknesses | CWE-269 | |
References |
| |
Metrics |
cvssV3_1
|
MITRE
Status: PUBLISHED
Assigner: Wordfence
Published: 2024-09-14T12:31:08.795Z
Updated: 2024-09-16T19:42:48.938Z
Reserved: 2024-07-03T16:05:30.839Z
Link: CVE-2024-6482
Vulnrichment
Updated: 2024-09-16T19:42:36.410Z
NVD
Status : Analyzed
Published: 2024-09-14T13:15:10.343
Modified: 2024-09-27T13:54:53.837
Link: CVE-2024-6482
Redhat
No data.