PT-2025-23375 · WordPress · Proforti
Kenneth Dunn
·
Published
2025-05-31
·
Updated
2025-06-05
·
CVE-2025-4631
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Proforti plugin for WordPress versions 2.0.6.0 through 2.1.1.3
Description
The issue is related to a missing capability check on the "stocktend object" endpoint. This allows unauthenticated attackers to trigger the
save object as user() function for objects whose datatype is set to 'users'. As a result, attackers can write arbitrary strings into the user's wp capabilities meta field, potentially elevating the privileges of an existing user account or a newly created one to that of an administrator.Recommendations
For versions 2.0.6.0 through 2.1.1.3, update to a patched version to resolve the issue. As a temporary workaround, consider disabling access to the "stocktend object" endpoint until a patch is available. Restrict access to the
save object as user() function to minimize the risk of exploitation. Avoid using the datatype variable with the value 'users' in the affected endpoint until the issue is resolved.Fix
LPE
Improper Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Proforti