Record summary

CVE-2024-2172 has a selected CVSS score of 9.8 (critical).

Description

The Malware Scanner plugin and the Web Application Firewall plugin for WordPress (both by MiniOrange) are vulnerable to privilege escalation due to a missing capability check on the mo_wpns_init() function in all versions up to, and including, 4.7.2 (for Malware Scanner) and 2.1.1 (for Web Application Firewall). This makes it possible for unauthenticated attackers to escalate their privileges to that of an administrator.

Description source: CVE List

Exploitation context

Known exploitation

VulnCheck KEV
Listed · Mar 21, 2024 · VulnCheck
Reported exploitation
Observed · VulnCheck

CISA SSVC decision

ExploitationNone
AutomatableYes
Technical impactTotal

CISA Coordinator · SSVC 2.0.3 · Evaluated Mar 13, 2024 · Source: CVE List

Affected products and versions

5
ProductSourceVersion rangeStatus

Malware Scanner plugin and Web Application Firewall plugin for WordPress

Browse MiniOrange / Malware Scanner plugin and Web Application Firewall plugin for WordPress
VulnCheckVersion data not supplied

Default status: unaffected

CVE ListThrough 4.7.2affected

Web Application Firewall – website security

Browse cyberlord92 / Web Application Firewall – website security

Default status: unaffected

CVE ListThrough 2.1.1affected

Default status: unknown

CVE ListThrough 4.7.2affected

Default status: unknown

CVE ListThrough 2.1.1affected

References

6