nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2024-11951 CVE-2024-11951
CRITICAL
Homey Login Register <= 2.4.0 - Unauthenticated Privilege Escalation in homey_register
Record summary
CVE-2024-11951 has a selected CVSS score of 9.8 (critical).
Description
The Homey Login Register plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including, 2.4.0. This is due to the plugin allowing users who are registering new accounts to set their own role. This makes it possible for unauthenticated attackers to gain elevated privileges by creating an account with the administrator role.
Description source: CVE List
Exploitation context
Known exploitation
- VulnCheck KEV
- Listed · Mar 5, 2025 · VulnCheck
- Reported exploitation
- Observed · VulnCheck
CISA SSVC decision
ExploitationNone
AutomatableYes
Technical impactTotal
CISA Coordinator · SSVC 2.0.3 · Evaluated Mar 5, 2025 · Source: CVE List
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
Homey Login RegisterBrowse Fave Themes / Homey Login RegisterDefault status: unaffected | VulnCheck, CVE List | Through 2.4.0 | affected |
References
3themeforest.net
https://themeforest.net/item/homey-booking-wordpress-theme/23338013 wordfence.com
https://www.wordfence.com/threat-intel/vulnerabilities/id/67c4066f-b8bc-4cd0-ae47-844af23e003f?source=cve