CVE-2024-2172
Malware Scanner <= 4.7.2 and Web Application Firewall <= 2.1.1 - Unauthenticated Privilege Escalation
Record summary
CVE-2024-2172 has a selected CVSS score of 9.8 (critical).
Description
The Malware Scanner plugin and the Web Application Firewall plugin for WordPress (both by MiniOrange) are vulnerable to privilege escalation due to a missing capability check on the mo_wpns_init() function in all versions up to, and including, 4.7.2 (for Malware Scanner) and 2.1.1 (for Web Application Firewall). This makes it possible for unauthenticated attackers to escalate their privileges to that of an administrator.
Exploitation context
Known exploitation
- VulnCheck KEV
- Listed · Mar 21, 2024 · VulnCheck
- Reported exploitation
- Observed · VulnCheck
CISA SSVC decision
CISA Coordinator · SSVC 2.0.3 · Evaluated Mar 13, 2024 · Source: CVE List
Affected products and versions
5| Product | Source | Version range | Status |
|---|---|---|---|
Malware Scanner plugin and Web Application Firewall plugin for WordPressBrowse MiniOrange / Malware Scanner plugin and Web Application Firewall plugin for WordPress | VulnCheck | Version data not supplied | |
Malware ScannerBrowse cyberlord92 / Malware ScannerDefault status: unaffected | CVE List | Through 4.7.2 | affected |
Web Application Firewall – website securityBrowse cyberlord92 / Web Application Firewall – website securityDefault status: unaffected | CVE List | Through 2.1.1 | affected |
malware_scannerBrowse miniorange / malware_scannerDefault status: unknown | CVE List | Through 4.7.2 | affected |
web_application_firewallBrowse miniorange / web_application_firewallDefault status: unknown | CVE List | Through 2.1.1 | affected |