CVE-2024-11643

HIGH

WordPress AllAccessible <1.3.4 - Privilege Escalation

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2024-11643. PoCs published by RandomRobbieBF.

AI-analyzed exploit summary The repository contains a functional proof-of-concept exploit for CVE-2024-11643, demonstrating how an authenticated attacker with Subscriber-level access can update arbitrary WordPress options via the 'AllAccessible_save_settings' function, leading to privilege escalation.

Description

The Accessibility by AllAccessible plugin for WordPress is vulnerable to unauthorized modification of data that can lead to privilege escalation due to a missing capability check on the 'AllAccessible_save_settings' function in all versions up to, and including, 1.3.4. This makes it possible for authenticated attackers, with Subscriber-level access and above, to update arbitrary options on the WordPress site. This can be leveraged to update the default role for registration to administrator and enable user registration for attackers to gain administrative user access to a vulnerable site.

Exploits (1)

nomisec WORKING POC
by RandomRobbieBF · poc
https://github.com/RandomRobbieBF/CVE-2024-11643

The repository contains a functional proof-of-concept exploit for CVE-2024-11643, demonstrating how an authenticated attacker with Subscriber-level access can update arbitrary WordPress options via the 'AllAccessible_save_settings' function, leading to privilege escalation.

Classification
Working Poc 95%
Attack Type
Auth Bypass
Complexity
Trivial
Reliability
Reliable
Target: Accessibility by AllAccessible WordPress plugin <= 1.3.4
Auth required
Prerequisites: Authenticated access as a Subscriber or higher
devstral-2 · analyzed Feb 18, 2026 Full analysis →

Scores

CVSS v3 8.8
EPSS 0.0070
EPSS Percentile 48.4%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-862
Status published
Products (1)
allaccessible/Accessibility by AllAccessible < 1.3.4
Published Dec 04, 2024
Tracked Since Feb 18, 2026