Exploitation Summary
EIP tracks 1 public exploit for CVE-2020-13693. PoCs published by Raphael Karger.
AI-analyzed exploit summary This exploit leverages an unauthenticated privilege escalation vulnerability in BBPress < 2.5 by manipulating the registration process to assign the 'bbp_keymaster' role. It extracts a nonce from the login page and submits a crafted POST request to create an admin-level user.
Description
An unauthenticated privilege-escalation issue exists in the bbPress plugin before 2.6.5 for WordPress when New User Registration is enabled.
Exploits (1)
This exploit leverages an unauthenticated privilege escalation vulnerability in BBPress < 2.5 by manipulating the registration process to assign the 'bbp_keymaster' role. It extracts a nonce from the login page and submits a crafted POST request to create an admin-level user.
References (4)
Scores
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H