The Post Form – Registration Form – Profile Form for User Profiles – Frontend Content Forms for User Submissions (UGC) plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including, 2.8.11. This is due to plugin not properly restricting what users have access to set the default role on registration forms. This makes it possible for authenticated attackers, with contributor-level access and above, to create a registration form with a custom role that allows them to register as administrators.
History

Tue, 17 Sep 2024 02:30:00 +0000

Type Values Removed Values Added
First Time appeared Themekraft
Themekraft post Form Registration Form Profile Form For User Profiles And Content Forms
CPEs cpe:2.3:a:themekraft:post_form_registration_form_profile_form_for_user_profiles_and_content_forms:*:*:*:*:*:wordpress:*:*
Vendors & Products Themekraft
Themekraft post Form Registration Form Profile Form For User Profiles And Content Forms
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Sat, 14 Sep 2024 03:30:00 +0000

Type Values Removed Values Added
Description The Post Form – Registration Form – Profile Form for User Profiles – Frontend Content Forms for User Submissions (UGC) plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including, 2.8.11. This is due to plugin not properly restricting what users have access to set the default role on registration forms. This makes it possible for authenticated attackers, with contributor-level access and above, to create a registration form with a custom role that allows them to register as administrators.
Title Post Form – Registration Form – Profile Form for User Profiles – Frontend Content Forms for User Submissions (UGC) <= 2.8.11 - Authenticated (Contributor+) Privilege Escalation
Weaknesses CWE-269
References
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: Wordfence

Published: 2024-09-14T03:19:27.488Z

Updated: 2024-09-16T19:09:35.192Z

Reserved: 2024-08-27T21:04:46.301Z

Link: CVE-2024-8246

cve-icon Vulnrichment

Updated: 2024-09-16T19:09:30.582Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2024-09-14T04:15:04.493

Modified: 2024-09-14T11:47:14.677

Link: CVE-2024-8246

cve-icon Redhat

No data.