nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2024-12281 CVE-2024-12281
CRITICAL
Homey <= 2.4.2 - Unauthenticated Privilege Escalation in homey_save_profile
Record summary
CVE-2024-12281 has a selected CVSS score of 9.8 (critical).
Description
The Homey theme for WordPress is vulnerable to privilege escalation in all versions up to, and including, 2.4.2. This is due to the plugin allowing users who are registering new accounts to set their own role. This makes it possible for unauthenticated attackers to gain elevated privileges by creating an account with the Administrator, Editor, or Shop Manager role.
Description source: CVE List
Exploitation context
Known exploitation
- VulnCheck KEV
- Listed · May 4, 2026 · VulnCheck
- Reported exploitation
- Observed · VulnCheck
CISA SSVC decision
ExploitationNone
AutomatableYes
Technical impactTotal
CISA Coordinator · SSVC 2.0.3 · Evaluated Mar 5, 2025 · Source: CVE List
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
Default status: unaffected | CVE List, VulnCheck | Through 2.4.2 | affected |
References
3themeforest.net
https://themeforest.net/item/homey-booking-wordpress-theme/23338013 wordfence.com
https://www.wordfence.com/threat-intel/vulnerabilities/id/3b93c33c-4ab1-48a2-b84d-3cb38ccea829?source=cve