CVE-2024-8485

CRITICAL

WordPress <4.7.1 - Privilege Escalation

Title source: llm
STIX 2.1

Description

The REST API TO MiniProgram plugin for WordPress is vulnerable to privilege escalation via account takeovr in all versions up to, and including, 4.7.1 via the updateUserInfo() due to missing validation on the 'openid' user controlled key that determines what user will be updated. This makes it possible for unauthenticated attackers to update arbitrary user's accounts, including their email to a @weixin.com email, which can the be leveraged to reset the password of the user's account, including administrators.

Scores

CVSS v3 9.8
EPSS 0.0036
EPSS Percentile 58.0%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact total

Details

CWE
CWE-639
Status published
Products (2)
jianbo/rest_api_to_miniprogram < 4.7.1
xjb/REST API TO MiniProgram < 4.7.1
Published Sep 25, 2024
Tracked Since Feb 18, 2026