PT-2019-7148 · WordPress · Wp Marketplace

Kacper Szurek

·

Published

2019-11-06

·

Updated

2019-11-08

·

CVE-2014-9013

CVSS v2.0

6.5

Medium

VectorAV:N/AC:L/Au:S/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions WP Marketplace plugin version 2.4.0
Description The issue allows remote authenticated users to create arbitrary users and gain admin privileges. This is achieved through the ajaxinit function in wpmarketplace/libs/cart.php by sending a request to "wpmp pp ajax call" with an execution target of wp insert user.
Recommendations For WP Marketplace plugin version 2.4.0, consider disabling the ajaxinit function in wpmarketplace/libs/cart.php as a temporary workaround until a patch is available. Restrict access to the "wpmp pp ajax call" endpoint to minimize the risk of exploitation. Avoid using the wp insert user execution target in the affected endpoint until the issue is resolved.

Exploit

Fix

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2014-9013

Affected Products

Wp Marketplace