PT-2024-14143 · WordPress · Wp-Buy Login As User/Customer

Rafie Muhammad

·

Published

2024-04-25

·

Updated

2024-07-10

·

CVE-2023-51484

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions wp-buy Login as User or Customer (User Switching) versions n/a through 3.8
Description The issue is related to an Improper Authentication vulnerability that allows Privilege Escalation. This vulnerability can be exploited to escalate privileges.
Recommendations For versions n/a through 3.8, update to a version later than 3.8 to resolve the issue. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Improper Authentication

Incorrect Privilege Assignment

Weakness Enumeration

Related Identifiers

CVE-2023-51484

Affected Products

Wp-Buy Login As User/Customer