CVE-2024-6624
JSON API User <= 3.9.3 - Unauthenticated Privilege Escalation
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
1Exploited in Wild
-Decision
Descriptions
The JSON API User plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including, 3.9.3. This is due to improper controls on custom user meta fields. This makes it possible for unauthenticated attackers to register as administrators on the site. The plugin requires the JSON API plugin to also be installed.
El complemento JSON API User para WordPress es vulnerable a la escalada de privilegios en todas las versiones hasta la 3.9.3 incluida. Esto se debe a controles inadecuados en los metacampos de usuario personalizados. Esto hace posible que atacantes no autenticados se registren como administradores en el sitio. El complemento requiere que también esté instalado el complemento JSON API.
CVSS Scores
SSVC
- Decision:Attend
Timeline
- 2024-07-09 CVE Reserved
- 2024-07-10 CVE Published
- 2024-08-01 CVE Updated
- 2024-09-10 First Exploit
- 2024-12-17 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
- CWE-269: Improper Privilege Management
CAPEC
References (5)
URL | Date | SRC |
---|---|---|
https://github.com/RandomRobbieBF/CVE-2024-6624 | 2024-09-10 |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Parorrey Search vendor "Parorrey" | JSON API User Search vendor "Parorrey" for product "JSON API User" | <= 3.9.3 Search vendor "Parorrey" for product "JSON API User" and version " <= 3.9.3" | en |
Affected
|