The UserPro plugin for WordPress is vulnerable to privilege escalation in versions up to, and including, 3.6.0 due to the insecure 'administrator' default value for the 'default_user_role' option. This makes it possible for unauthenticated attackers to register an administrator user even if the registration form is disabled.
History

Thu, 17 Oct 2024 16:15:00 +0000

Type Values Removed Values Added
First Time appeared Miniorange
Miniorange otp Verification
CPEs cpe:2.3:a:miniorange:otp_verification:*:*:*:*:*:*:*:*
Vendors & Products Miniorange
Miniorange otp Verification
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 17 Oct 2024 02:15:00 +0000

Type Values Removed Values Added
Description The UserPro plugin for WordPress is vulnerable to privilege escalation in versions up to, and including, 3.6.0 due to the insecure 'administrator' default value for the 'default_user_role' option. This makes it possible for unauthenticated attackers to register an administrator user even if the registration form is disabled.
Title Miniorange OTP Verification with Firebase <= 3.6.0 - Privilege Escalation via Registration due to Administrator Default User Role Value
Weaknesses CWE-266
References
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: Wordfence

Published: 2024-10-17T02:06:05.842Z

Updated: 2024-10-17T15:48:42.152Z

Reserved: 2024-10-11T12:46:24.289Z

Link: CVE-2024-9863

cve-icon Vulnrichment

Updated: 2024-10-17T15:48:31.396Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2024-10-17T02:15:04.030

Modified: 2024-10-18T12:53:04.627

Link: CVE-2024-9863

cve-icon Redhat

No data.