8.8
CVE-2021-24289
- EPSS 1.01%
- Veröffentlicht 17.05.2021 17:15:08
- Zuletzt bearbeitet 21.11.2024 05:52:46
- Quelle contact@wpscan.com
- CVE-Watchlists
- Unerledigt
Store Locator Plus <= 5.5.15 - Authenticated Privilege Escalation
There is functionality in the Store Locator Plus for WordPress plugin through 5.5.14 that made it possible for authenticated users to update their user meta data to become an administrator on any site using the plugin.
Mögliche Gegenmaßnahme
Store Locator Plus® for WordPress: Update to version 5.7, or a newer patched version
Weitere Schwachstelleninformationen
SystemWordPress Plugin
≫
Produkt
Store Locator Plus® for WordPress
Version
*-5.5.15
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
De-baat ≫ Store Locator Plus SwPlatformwordpress Version <= 5.5.14
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 1.01% | 0.762 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 8.8 | 2.8 | 5.9 |
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
|
| nvd@nist.gov | 6.5 | 8 | 6.4 |
AV:N/AC:L/Au:S/C:P/I:P/A:P
|
CWE-269 Improper Privilege Management
The product does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control for that actor.