Описание
The WPCOM Member plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including, 1.5.2.1. This is due to the plugin allowing arbitrary data to be passed to wp_insert_user() during registration. This makes it possible for unauthenticated attackers to update their role to that of an administrator during registration.
Уязвимые конфигурации
Конфигурация 1Версия до 1.5.3 (исключая)
cpe:2.3:a:wpcom:wpcom_member:*:*:*:*:*:wordpress:*:*
EPSS
Процентиль: 77%
0.01021
Низкий
9.8 Critical
CVSS3
Дефекты
CWE-269
NVD-CWE-noinfo
Связанные уязвимости
CVSS3: 9.8
github
больше 1 года назад
The WPCOM Member plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including, 1.5.2.1. This is due to the plugin allowing arbitrary data to be passed to wp_insert_user() during registration. This makes it possible for unauthenticated attackers to update their role to that of an administrator during registration.
EPSS
Процентиль: 77%
0.01021
Низкий
9.8 Critical
CVSS3
Дефекты
CWE-269
NVD-CWE-noinfo