CVE-2024-8853

CRITICAL

Webo-facto <= 1.40 - Unauthenticated Privilege Escalation via Username Manipulation

Title source: llm
STIX 2.1

Description

The Webo-facto plugin for WordPress is vulnerable to privilege escalation in versions up to, and including, 1.40 due to insufficient restriction on the 'doSsoAuthentification' function. This makes it possible for unauthenticated attackers to make themselves administrators by registering with a username that contains '-wfuser'.

Scores

CVSS v3 9.8
EPSS 0.0065
EPSS Percentile 46.1%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact total

Details

CWE
CWE-269
Status published
Products (2)
jeremieglotin/Webo-facto < 1.40
medialibs/webo-facto < 1.41
Published Sep 20, 2024
Tracked Since Feb 18, 2026