The Wux Blog Editor plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 3.0.0. This is due to missing validation on the token being supplied during the autologin through the plugin. This makes it possible for unauthenticated attackers to log in to the first administrator user.
Metrics
Affected Vendors & Products
References
History
Mon, 28 Oct 2024 20:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Jurre De Klijn
Jurre De Klijn wux Blog Editor |
|
CPEs | cpe:2.3:a:jurre_de_klijn:wux_blog_editor:*:*:*:*:*:*:*:* | |
Vendors & Products |
Jurre De Klijn
Jurre De Klijn wux Blog Editor |
|
Metrics |
ssvc
|
Sat, 26 Oct 2024 02:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | The Wux Blog Editor plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 3.0.0. This is due to missing validation on the token being supplied during the autologin through the plugin. This makes it possible for unauthenticated attackers to log in to the first administrator user. | |
Title | Wux Blog Editor <= 3.0.0 - Authentication Bypass to Administrator | |
Weaknesses | CWE-288 | |
References |
| |
Metrics |
cvssV3_1
|
MITRE
Status: PUBLISHED
Assigner: Wordfence
Published: 2024-10-26T01:58:34.373Z
Updated: 2024-10-28T19:40:11.760Z
Reserved: 2024-10-14T11:53:29.303Z
Link: CVE-2024-9931
Vulnrichment
Updated: 2024-10-28T19:39:45.592Z
NVD
Status : Awaiting Analysis
Published: 2024-10-26T03:15:04.770
Modified: 2024-10-28T13:58:09.230
Link: CVE-2024-9931
Redhat
No data.