Exploitation Summary
EIP tracks 2 public exploits for CVE-2024-6624. PoCs published by RandomRobbieBF, Jenderal92.
AI-analyzed exploit summary This PoC exploits an unauthenticated privilege escalation vulnerability in the WordPress JSON API User plugin (versions <= 3.9.3) by registering a new user and then updating their metadata to grant administrator privileges. The exploit leverages improper controls on custom user meta fields.
Description
The JSON API User plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including, 3.9.3. This is due to improper controls on custom user meta fields. This makes it possible for unauthenticated attackers to register as administrators on the site. The plugin requires the JSON API plugin to also be installed.
Exploits (2)
This PoC exploits an unauthenticated privilege escalation vulnerability in the WordPress JSON API User plugin (versions <= 3.9.3) by registering a new user and then updating their metadata to grant administrator privileges. The exploit leverages improper controls on custom user meta fields.
This Python script exploits CVE-2024-6624, an unauthenticated privilege escalation vulnerability in the JSON API User WordPress plugin (versions <= 3.9.3). It automates user registration and privilege escalation to administrator by leveraging insecure nonce generation and user meta updates.
References (4)
Scores
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H