Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-mcrr-9jjf-26v7

Опубликовано: 25 апр. 2025
Источник: github
Github: Не прошло ревью
CVSS3: 9.8

Описание

The Service Finder Bookings plugin for WordPress, used by the Service Finder - Directory and Job Board WordPress Theme, is vulnerable to privilege escalation in all versions up to, and including, 5.1. This is due to a lack of restriction on user role in the 'nsl_registration_store_extra_input' function. This makes it possible for unauthenticated attackers to register an account on the site with an arbitrary role, including Administrator, when registering via a social login. The Nextend Social Login plugin must be installed and configured to exploit the vulnerability.

The Service Finder Bookings plugin for WordPress, used by the Service Finder - Directory and Job Board WordPress Theme, is vulnerable to privilege escalation in all versions up to, and including, 5.1. This is due to a lack of restriction on user role in the 'nsl_registration_store_extra_input' function. This makes it possible for unauthenticated attackers to register an account on the site with an arbitrary role, including Administrator, when registering via a social login. The Nextend Social Login plugin must be installed and configured to exploit the vulnerability.

EPSS

Процентиль: 50%
0.00266
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-266

Связанные уязвимости

CVSS3: 9.8
nvd
10 месяцев назад

The Service Finder Bookings plugin for WordPress, used by the Service Finder - Directory and Job Board WordPress Theme, is vulnerable to privilege escalation in all versions up to, and including, 5.1. This is due to a lack of restriction on user role in the 'nsl_registration_store_extra_input' function. This makes it possible for unauthenticated attackers to register an account on the site with an arbitrary role, including Administrator, when registering via a social login. The Nextend Social Login plugin must be installed and configured to exploit the vulnerability.

EPSS

Процентиль: 50%
0.00266
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-266