Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-cc3h-2hrf-w63x

Опубликовано: 17 окт. 2024
Источник: github
Github: Не прошло ревью
CVSS3: 9.8

Описание

The UserPro plugin for WordPress is vulnerable to privilege escalation in versions up to, and including, 3.6.0 due to the insecure 'administrator' default value for the 'default_user_role' option. This makes it possible for unauthenticated attackers to register an administrator user even if the registration form is disabled.

The UserPro plugin for WordPress is vulnerable to privilege escalation in versions up to, and including, 3.6.0 due to the insecure 'administrator' default value for the 'default_user_role' option. This makes it possible for unauthenticated attackers to register an administrator user even if the registration form is disabled.

EPSS

Процентиль: 65%
0.00499
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-266

Связанные уязвимости

CVSS3: 9.8
nvd
больше 1 года назад

The UserPro plugin for WordPress is vulnerable to privilege escalation in versions up to, and including, 3.6.0 due to the insecure 'administrator' default value for the 'default_user_role' option. This makes it possible for unauthenticated attackers to register an administrator user even if the registration form is disabled.

EPSS

Процентиль: 65%
0.00499
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-266