Fave Themes Vulnerabilities and Affected Products
Vulnerabilities associated with Homey Login Register.
Products
Clear product- Homey5 vulnerabilities
- Homey Login Register1 vulnerability
| Vulnerability | Title and context | CVSS | EPSS | PoCs | Signals | STIX action |
|---|---|---|---|---|---|---|
CVE-2024-11951CRITICAL | Homey Login Register <= 2.4.0 - Unauthenticated Privilege Escalation in homey_registerThe Homey Login Register plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including, 2.4.0. This is due to the plugin allowing users who are registering new accounts to set their own role. This makes it possible for unauthenticated attackers to gain elevated privileges by creating an account with the administrator role. CWE-269Mar 5, 2025 | CVSS9.8v3.1 | EPSS0.419% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |