CVE-2023-26009
WordPress Houzez Login Register plugin <= 2.6.3 - Privilege Escalation
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
Improper Privilege Management vulnerability in favethemes Houzez Login Register allows Privilege Escalation.This issue affects Houzez Login Register: from n/a through 2.6.3.
Vulnerabilidad de gestiĆ³n de privilegios incorrecta en favethemes Houzez Login Register permite la escalada de privilegios. Este problema afecta a Houzez Login Register: desde n/a hasta 2.6.3.
The Houzez Login Register plugin for WordPress is vulnerable to privilege escalation in versions up to, and including, 2.6.3. This is due to improper assignment of privileges on user registration that allows users to supply their own role via the houzez_register AJAX action. This makes it possible for unauthenticated attackers to register as administrators on vulnerable sites.
CVSS Scores
SSVC
- Decision:Attend
Timeline
- 2023-02-17 CVE Reserved
- 2023-02-23 CVE Published
- 2024-05-17 EPSS Updated
- 2024-08-02 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-269: Improper Privilege Management
CAPEC
- CAPEC-233: Privilege Escalation
References (1)
URL | Tag | Source |
---|---|---|
https://patchstack.com/database/vulnerability/houzez-login-register/wordpress-houzez-login-register-plugin-2-6-3-privilege-escalation?_s_id=cve | Vdb Entry |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Houzez Login Register Search vendor "Houzez Login Register" | Houzez Login Register Search vendor "Houzez Login Register" for product "Houzez Login Register" | >= 0.0.0 <= 2.6.3 Search vendor "Houzez Login Register" for product "Houzez Login Register" and version " >= 0.0.0 <= 2.6.3" | en |
Affected
|