Exploitation Summary
EIP tracks 1 public exploit for CVE-2024-54379. PoCs published by RandomRobbieBF.
AI-analyzed exploit summary This PoC demonstrates a missing authorization vulnerability in the Minterpress WordPress plugin (≤1.0.5), allowing authenticated attackers with Subscriber+ privileges to update arbitrary options via an AJAX endpoint, enabling privilege escalation by setting the default role to administrator and enabling user registration.
Description
Missing Authorization vulnerability in blokhauswp Minterpress minterpress allows Privilege Escalation.This issue affects Minterpress: from n/a through <= 1.0.5.
Exploits (1)
This PoC demonstrates a missing authorization vulnerability in the Minterpress WordPress plugin (≤1.0.5), allowing authenticated attackers with Subscriber+ privileges to update arbitrary options via an AJAX endpoint, enabling privilege escalation by setting the default role to administrator and enabling user registration.
References (2)
Scores
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H