PT-2024-16925 · WordPress · Adforest

Tonn

·

Published

2024-12-21

·

Updated

2025-08-12

·

CVE-2024-11349

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions AdForest theme for WordPress versions up to, and including, 5.1.6
Description The issue is related to authentication bypass due to the plugin not properly verifying a user's identity prior to authenticating them through the sb login user with otp fun() function. This allows unauthenticated attackers to log in as arbitrary users, including administrators.
Recommendations For AdForest theme for WordPress versions up to, and including, 5.1.6, update to a version later than 5.1.6 to resolve the issue. As a temporary workaround, consider disabling the sb login user with otp fun() function until a patch is available.

Fix

Authentication Bypass Using an Alternate Path or Channel

Weakness Enumeration

Related Identifiers

CVE-2024-11349

Affected Products

Adforest