The User Toolkit plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 1.2.3. This is due to an improper capability check in the 'switchUser' function. This makes it possible for authenticated attackers, with subscriber-level permissions and above, to log in as any existing user on the site, such as an administrator.
Metrics
Affected Vendors & Products
References
History
Mon, 28 Oct 2024 20:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Deryck Onate
Deryck Onate user Toolkit |
|
CPEs | cpe:2.3:a:deryck_onate:user_toolkit:*:*:*:*:*:*:*:* | |
Vendors & Products |
Deryck Onate
Deryck Onate user Toolkit |
|
Metrics |
ssvc
|
Sat, 26 Oct 2024 02:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | The User Toolkit plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 1.2.3. This is due to an improper capability check in the 'switchUser' function. This makes it possible for authenticated attackers, with subscriber-level permissions and above, to log in as any existing user on the site, such as an administrator. | |
Title | User Toolkit <= 1.2.3 - Authenticated (Subscriber+) Authentication Bypass | |
Weaknesses | CWE-288 | |
References |
| |
Metrics |
cvssV3_1
|
MITRE
Status: PUBLISHED
Assigner: Wordfence
Published: 2024-10-26T01:58:35.496Z
Updated: 2024-10-28T19:34:19.279Z
Reserved: 2024-10-11T19:30:44.330Z
Link: CVE-2024-9890
Vulnrichment
Updated: 2024-10-28T19:34:12.939Z
NVD
Status : Awaiting Analysis
Published: 2024-10-26T03:15:04.340
Modified: 2024-10-28T13:58:09.230
Link: CVE-2024-9890
Redhat
No data.