PT-2024-39479 · WordPress · Wordpress Video Robot

Tonn

·

Published

2024-11-15

·

Updated

2024-11-21

·

CVE-2024-9192

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions WordPress Video Robot - The Ultimate Video Importer plugin for WordPress versions up to and including 1.20.0
Description The issue is related to insufficient validation of user metadata that can be updated in the wpvr rate request result() function. This allows authenticated attackers with subscriber-level access and above to update their user metadata on a WordPress site, potentially escalating their privileges to those of an administrator.
Recommendations For WordPress Video Robot - The Ultimate Video Importer plugin for WordPress versions up to and including 1.20.0, update to a version higher than 1.20.0 to resolve the issue. As a temporary workaround, consider disabling the wpvr rate request result() function until a patch is available. Restrict access to the plugin's functionality to minimize the risk of exploitation.

Fix

Improper Privilege Management

Weakness Enumeration

Related Identifiers

CVE-2024-9192

Affected Products

Wordpress Video Robot