Record summary

CVE-2023-41954 has a selected CVSS score of 8.6 (high); EIP currently links 1 Nuclei template.

Description

Improper Privilege Management vulnerability in ProfilePress Membership Team ProfilePress allows Privilege Escalation.This issue affects ProfilePress: from n/a through 4.13.1.

Description source: CVE List

Exploitation context

Known exploitation

VulnCheck KEV
Listed · Sep 12, 2023 · VulnCheck
Reported exploitation
Observed · VulnCheck

Available material

Nuclei templates
1

CISA SSVC decision

ExploitationNone
AutomatableNo
Technical impactTotal

CISA Coordinator · SSVC 2.0.3 · Evaluated May 17, 2024 · Source: CVE List

Affected products and versions

2
ProductSourceVersion rangeStatus

Default status: unaffected

CVE ListThrough 4.13.1affected
VulnCheckVersion data not supplied

Nuclei templates

1
ProjectDiscoveryHIGHProfilePress <= 4.13.1 — Unauthenticated Privilege EscalationCVSS 8.6

Improper Privilege Management vulnerability in ProfilePress Membership Team ProfilePress allows Privilege Escalation.This issue affects ProfilePress: from n/a through 4.13.1.

Impact

Attackers can escalate privileges, gaining unauthorized access to restricted features or data within ProfilePress.

Remediation

Update to the latest version of ProfilePress to address privilege management issues.

WeaknessesCWE-269
Authorsdaffainfo
Template tagscvecve2023wordpresswpwp-pluginproperfractionprofilepressvkev
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:L
CPE: cpe:2.3:a:properfraction:profilepress:*:*:*:*:*:wordpress:*:*
Shodan: http.component:"profilepress"
FOFA: body="/wp-content/plugins/wp-user-avatar/"

Source: ProjectDiscovery

References

2