Логотип exploitDog
bind:CVE-2024-8420
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2024-8420

Количество 2

Количество 2

nvd логотип

CVE-2024-8420

12 месяцев назад

The DHVC Form plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including, 2.4.7. This is due to the plugin allowing a user to supply the 'role' field when registering. This makes it possible for unauthenticated attackers to register as an administrator on sites.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-w465-rmm3-535r

12 месяцев назад

The DHVC Form plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including, 2.4.7. This is due to the plugin allowing a user to supply the 'role' field when registering. This makes it possible for unauthenticated attackers to register as an administrator on sites.

CVSS3: 9.8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2024-8420

The DHVC Form plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including, 2.4.7. This is due to the plugin allowing a user to supply the 'role' field when registering. This makes it possible for unauthenticated attackers to register as an administrator on sites.

CVSS3: 9.8
1%
Низкий
12 месяцев назад
github логотип
GHSA-w465-rmm3-535r

The DHVC Form plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including, 2.4.7. This is due to the plugin allowing a user to supply the 'role' field when registering. This makes it possible for unauthenticated attackers to register as an administrator on sites.

CVSS3: 9.8
1%
Низкий
12 месяцев назад

Уязвимостей на страницу