CVE-2024-9890

HIGH

WordPress User Toolkit <1.2.3 - Auth Bypass

Title source: llm

Description

The User Toolkit plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 1.2.3. This is due to an improper capability check in the 'switchUser' function. This makes it possible for authenticated attackers, with subscriber-level permissions and above, to log in as any existing user on the site, such as an administrator.

Exploits (1)

nomisec WORKING POC
by RandomRobbieBF · poc
https://github.com/RandomRobbieBF/CVE-2024-9890

Scores

CVSS v3 8.8
EPSS 0.1123
EPSS Percentile 93.4%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Classification

CWE
CWE-288
Status draft

Timeline

Published Oct 26, 2024
Tracked Since Feb 18, 2026