The Mapster WP Maps plugin for WordPress is vulnerable to unauthorized modification of data that can lead to privilege escalation due to an insufficient capability check on the mapster_wp_maps_set_option_from_js() function in all versions up to, and including, 1.5.0. This makes it possible for authenticated attackers, with contributor-level access and above, to update arbitrary options on the WordPress site. This can be leveraged to update the default role for registration to administrator and enable user registration for attackers to gain administrative user access to a vulnerable site.
History

Tue, 05 Nov 2024 18:00:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:a:mapster:mapster_wp_maps:*:*:*:*:*:wordpress:*:*

Fri, 25 Oct 2024 14:15:00 +0000

Type Values Removed Values Added
First Time appeared Mapster
Mapster mapster Wp Maps
CPEs cpe:2.3:a:mapster:mapster_wp_maps:-:*:*:*:*:wordpress:*:*
Vendors & Products Mapster
Mapster mapster Wp Maps
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Fri, 25 Oct 2024 07:00:00 +0000

Type Values Removed Values Added
Description The Mapster WP Maps plugin for WordPress is vulnerable to unauthorized modification of data that can lead to privilege escalation due to an insufficient capability check on the mapster_wp_maps_set_option_from_js() function in all versions up to, and including, 1.5.0. This makes it possible for authenticated attackers, with contributor-level access and above, to update arbitrary options on the WordPress site. This can be leveraged to update the default role for registration to administrator and enable user registration for attackers to gain administrative user access to a vulnerable site.
Title Mapster WP Maps <= 1.5.0 - Incorrect Authorization to Authenticated (Contributor+) Arbitrary Options Update
Weaknesses CWE-285
References
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: Wordfence

Published: 2024-10-25T06:51:25.526Z

Updated: 2024-10-25T14:07:24.007Z

Reserved: 2024-09-26T18:48:42.399Z

Link: CVE-2024-9235

cve-icon Vulnrichment

Updated: 2024-10-25T14:07:18.397Z

cve-icon NVD

Status : Analyzed

Published: 2024-10-25T07:15:05.387

Modified: 2024-11-05T17:36:01.270

Link: CVE-2024-9235

cve-icon Redhat

No data.