The JetFormBuilder plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including, 3.3.4.1. This is due to improper restriction on user meta fields. This makes it possible for authenticated attackers, with administrator-level and above permissions, to register as super-admins on the sites configured as multi-sites.
Metrics
Affected Vendors & Products
References
History
Wed, 07 Aug 2024 16:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Crocoblock
Crocoblock jetelements |
|
CPEs | cpe:2.3:a:crocoblock:jetelements:*:*:*:*:*:wordpress:*:* | |
Vendors & Products |
Crocoblock
Crocoblock jetelements |
|
Metrics |
ssvc
|
MITRE
Status: PUBLISHED
Assigner: Wordfence
Published: 2024-08-03T06:41:39.862Z
Updated: 2024-08-07T15:57:47.794Z
Reserved: 2024-07-30T14:29:14.301Z
Link: CVE-2024-7291
Vulnrichment
Updated: 2024-08-07T15:57:36.455Z
NVD
Status : Awaiting Analysis
Published: 2024-08-03T07:16:25.923
Modified: 2024-08-05T12:41:45.957
Link: CVE-2024-7291
Redhat
No data.