CVE-2021-24289: Store Locator Plus <= 5.5.14 - Authenticated Privilege Escalation
There is functionality in the Store Locator Plus for WordPress plugin through 5.5.14 that made it possible for authenticated users to update their user meta data to become an administrator on any site using the plugin.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2021-24289?
CVE-2021-24289 is considered a high severity vulnerability due to its potential to allow authenticated users to gain administrative access.
How do I fix CVE-2021-24289?
To fix CVE-2021-24289, you should update the Store Locator Plus for WordPress plugin to a version higher than 5.5.14.
Who is affected by CVE-2021-24289?
CVE-2021-24289 affects users of the Store Locator Plus for WordPress plugin version 5.5.14 and earlier.
What types of attacks can CVE-2021-24289 enable?
CVE-2021-24289 can enable attacks that allow authenticated users to escalate their privileges to that of an administrator.
Are there any known exploits for CVE-2021-24289?
Yes, there are known exploits for CVE-2021-24289 that have been reported, which aim to take advantage of the vulnerability to gain unauthorized access.