The PowerPack Pro for Elementor plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including, 2.10.17. This is due to the plugin not restricting low privileged users from setting a default role for a registration form. This makes it possible for authenticated attackers, with contributor-level access and above, to create a registration form with administrator set as the default role and then register as an administrator.
References
Link | Resource |
---|---|
https://powerpackelements.com/change-logs/ | Release Notes |
https://www.wordfence.com/threat-intel/vulnerabilities/id/249ccc77-0daf-41bc-b5c5-991bf17d645d?source=cve | Third Party Advisory |
Configurations
History
No history.
Information
Published : 2024-06-08 05:15
Updated : 2024-07-23 19:39
NVD link : CVE-2024-3668
Mitre link : CVE-2024-3668
CVE.ORG link : CVE-2024-3668
JSON object : View
Products Affected
ideabox
- powerpack_addons_for_elementor
CWE
CWE-732
Incorrect Permission Assignment for Critical Resource