PT-2024-39895 · WordPress · Userpro

István Márton

·

Published

2024-10-16

·

Updated

2024-10-22

·

CVE-2024-9863

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions UserPro plugin for WordPress versions up to, and including, 3.6.0
Description The issue is related to privilege escalation due to the insecure 'administrator' default value for the default user role option. This allows unauthenticated attackers to register an administrator user, even if the registration form is disabled.
Recommendations For versions up to, and including, 3.6.0, update the default user role option to a secure value to prevent privilege escalation. As a temporary workaround, consider disabling user registration until a patch is available. Restrict access to the registration form to minimize the risk of exploitation.

Fix

Incorrect Privilege Assignment

Weakness Enumeration

Related Identifiers

CVE-2024-9863

Affected Products

Userpro