CVE Published: 17/10/2024 |
CVE Updated: 17/10/2024 |
CVE Year: 2024 Source: Wordfence |
Vendor: publishpress |
Product: Co-Authors, Multiple Authors and Guest Authors in an Author Box with PublishPress Authors Status : PUBLISHED
CVE-2024-9215 Description
The Co-Authors, Multiple Authors and Guest Authors in an Author Box with PublishPress Authors plugin for WordPress is vulnerable to Insecure Direct Object Reference to Privilege Escalation/Account Takeover in all versions up to, and including, 4.7.1 via the action_edited_author() due to missing validation on the \'authors-user_id\' user controlled key. This makes it possible for authenticated attackers, with Author-level access and above, to update arbitrary user accounts email addresses, including administrators, which can then be leveraged to reset that user\'s account password and gain access.
Metrics
CVSS Version: 3.1 |
Base Score: 8.8 HIGH Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H