CVE-2023-47682
WordPress WP User Frontend plugin <= 3.6.5 - Authenticated Privilege Escalation vulnerability
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
Improper Privilege Management vulnerability in weDevs WP User Frontend allows Privilege Escalation.This issue affects WP User Frontend: from n/a through 3.6.5.
Una vulnerabilidad de gestión de privilegios incorrecta en la interfaz de usuario de WP de weDevs permite la escalada de privilegios. Este problema afecta la interfaz de usuario de WP: desde n/a hasta 3.6.5.
The WP User Frontend – Registration, User Profile, Membership, Content Restriction, User Directory, and Frontend Post Submission Plugin plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 3.6.5. This is due to the plugin not providing sufficient controls on the ability to supply a role on the registration form shortcode rendered via the registration_form function. This makes it possible for authenticated attackers, with author-level access and above, to add a registration form to a page with the role set to administrator and then subsequently use the form to register as an administrator.
CVSS Scores
SSVC
- Decision:Track*
Timeline
- 2023-11-08 CVE Reserved
- 2023-11-09 CVE Published
- 2024-05-18 EPSS Updated
- 2024-08-02 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-269: Improper Privilege Management
CAPEC
- CAPEC-233: Privilege Escalation
References (1)
URL | Tag | Source |
---|---|---|
https://patchstack.com/database/vulnerability/wp-user-frontend/wordpress-wp-user-frontend-plugin-3-6-5-authenticated-privilege-escalation-vulnerability?_s_id=cve | Vdb Entry |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Wp User Frontend Search vendor "Wp User Frontend" | Wp User Frontend Search vendor "Wp User Frontend" for product "Wp User Frontend" | >= 0.0.0 <= 3.6.5 Search vendor "Wp User Frontend" for product "Wp User Frontend" and version " >= 0.0.0 <= 3.6.5" | en |
Affected
|