PT-2025-9824 · WordPress · Homey

Tonn

·

Published

2025-03-05

·

Updated

2025-03-06

·

CVE-2024-12281

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Homey theme for WordPress versions prior to 2.4.3
Description The issue allows unauthenticated attackers to gain elevated privileges by creating an account with the Editor or Shop Manager role, due to the plugin permitting users who are registering new accounts to set their own role.
Recommendations For versions prior to 2.4.3, update to version 2.4.3 or later to resolve the issue.

Fix

LPE

Improper Privilege Management

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2024-12281

Affected Products

Homey