PT-2024-39277 · WordPress · Webo-Facto

István Márton

·

Published

2024-09-20

·

Updated

2024-09-25

·

CVE-2024-8853

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions: Webo-facto plugin for WordPress versions up to, and including, 1.40
Description: The Webo-facto plugin for WordPress has a privilege escalation issue due to insufficient restriction on the doSsoAuthentification function. This allows unauthenticated attackers to make themselves administrators by registering with a username that contains -wfuser.
Recommendations: For versions up to, and including, 1.40, consider disabling the doSsoAuthentification function until a patch is available to prevent exploitation. Restrict access to user registration with usernames containing -wfuser to minimize the risk of privilege escalation. Update to a version that fixes this issue once it becomes available. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Improper Privilege Management

Weakness Enumeration

Related Identifiers

CVE-2024-8853

Affected Products

Webo-Facto