CVE-2024-54379

HIGH

Blokhaus Minterpress <1.0.5 - Privilege Escalation

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2024-54379. PoCs published by RandomRobbieBF.

AI-analyzed exploit summary This PoC demonstrates a missing authorization vulnerability in the Minterpress WordPress plugin (≤1.0.5), allowing authenticated attackers with Subscriber+ privileges to update arbitrary options via an AJAX endpoint, enabling privilege escalation by setting the default role to administrator and enabling user registration.

Description

Missing Authorization vulnerability in blokhauswp Minterpress minterpress allows Privilege Escalation.This issue affects Minterpress: from n/a through <= 1.0.5.

Exploits (1)

nomisec WORKING POC
by RandomRobbieBF · poc
https://github.com/RandomRobbieBF/CVE-2024-54379

This PoC demonstrates a missing authorization vulnerability in the Minterpress WordPress plugin (≤1.0.5), allowing authenticated attackers with Subscriber+ privileges to update arbitrary options via an AJAX endpoint, enabling privilege escalation by setting the default role to administrator and enabling user registration.

Classification
Working Poc 95%
Attack Type
Auth Bypass
Complexity
Trivial
Reliability
Reliable
Target: Minterpress WordPress plugin ≤1.0.5
Auth required
Prerequisites: Authenticated WordPress user with Subscriber-level access or higher · Minterpress plugin version ≤1.0.5 installed
devstral-2 · analyzed Feb 16, 2026 Full analysis →

Scores

CVSS v3 8.8
EPSS 0.0074
EPSS Percentile 49.6%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-862
Status published
Products (2)
Blokhaus/Minterpress < 1.0.5
blokhauswp/Minterpress < 1.0.5
Published Dec 16, 2024
Tracked Since Feb 18, 2026