Description
The WordPress Video Robot - The Ultimate Video Importer plugin for WordPress is vulnerable to privilege escalation due to insufficient validation on user meta that can be updated in the wpvr_rate_request_result() function in all versions up to, and including, 1.20.0. This makes it possible for authenticated attackers, with subscriber-level access and above, to update their user meta on a WordPress site. This can be leveraged to update their capabilities to that of an administrator.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-50280 | The WordPress Video Robot - The Ultimate Video Importer plugin for WordPress is vulnerable to privilege escalation due to insufficient validation on user meta that can be updated in the wpvr_rate_request_result() function in all versions up to, and including, 1.20.0. This makes it possible for authenticated attackers, with subscriber-level access and above, to update their user meta on a WordPress site. This can be leveraged to update their capabilities to that of an administrator. |
References
History
Tue, 19 Nov 2024 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Pressaholic
Pressaholic wordpress Video Robot |
|
| CPEs | cpe:2.3:a:pressaholic:wordpress_video_robot:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Pressaholic
Pressaholic wordpress Video Robot |
|
| Metrics |
ssvc
|
Sat, 16 Nov 2024 03:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The WordPress Video Robot - The Ultimate Video Importer plugin for WordPress is vulnerable to privilege escalation due to insufficient validation on user meta that can be updated in the wpvr_rate_request_result() function in all versions up to, and including, 1.20.0. This makes it possible for authenticated attackers, with subscriber-level access and above, to update their user meta on a WordPress site. This can be leveraged to update their capabilities to that of an administrator. | |
| Title | WP Video Robot <= 1.20.0 - Authenticated (Subscriber+) Privilege Escalation via User Meta Update | |
| Weaknesses | CWE-269 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: Wordfence
Published:
Updated: 2026-04-08T16:44:14.140Z
Reserved: 2024-09-25T20:49:18.780Z
Link: CVE-2024-9192
Updated: 2024-11-18T21:52:51.932Z
Status : Deferred
Published: 2024-11-16T04:15:06.813
Modified: 2026-04-15T00:35:42.020
Link: CVE-2024-9192
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD