CVE-2023-41954
WordPress ProfilePress plugin <= 4.13.1 - Unauthenticated Limited Privilege Escalation vulnerability
Record summary
CVE-2023-41954 has a selected CVSS score of 8.6 (high); EIP currently links 1 Nuclei template.
Description
Improper Privilege Management vulnerability in ProfilePress Membership Team ProfilePress allows Privilege Escalation.This issue affects ProfilePress: from n/a through 4.13.1.
Exploitation context
Known exploitation
- VulnCheck KEV
- Listed · Sep 12, 2023 · VulnCheck
- Reported exploitation
- Observed · VulnCheck
Available material
- Nuclei templates
- 1
CISA SSVC decision
CISA Coordinator · SSVC 2.0.3 · Evaluated May 17, 2024 · Source: CVE List
Affected products and versions
2| Product | Source | Version range | Status |
|---|---|---|---|
Default status: unaffected | CVE List | Through 4.13.1 | affected |
ProfilePress PluginBrowse ProfilePress Membership Team / ProfilePress Plugin | VulnCheck | Version data not supplied | |
Nuclei templates
1ProjectDiscoveryHIGHProfilePress <= 4.13.1 — Unauthenticated Privilege EscalationCVSS 8.6
Improper Privilege Management vulnerability in ProfilePress Membership Team ProfilePress allows Privilege Escalation.This issue affects ProfilePress: from n/a through 4.13.1.
Impact
Attackers can escalate privileges, gaining unauthorized access to restricted features or data within ProfilePress.
Remediation
Update to the latest version of ProfilePress to address privilege management issues.
Source: ProjectDiscovery