First published: Mon Nov 21 2022(Updated: )
The WP User Frontend WordPress plugin before 3.5.29 uses a user supplied argument called urhidden in its registration form, which contains the role for the account to be created with, encrypted via wpuf_encryption(). This could allow an attacker having access to the AUTH_KEY and AUTH_SALT constant (via an arbitrary file access issue for example, or if the blog is using the default keys) to create an account with any role they want, such as admin
Credit: contact@wpscan.com
Affected Software | Affected Version | How to fix |
---|---|---|
Wedevs Wp User Frontend | <3.5.29 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID of this WP User Frontend WordPress plugin vulnerability is CVE-2021-24649.
The severity of CVE-2021-24649 is critical with a CVSS score of 9.8.
The affected software of CVE-2021-24649 is the WP User Frontend WordPress plugin version up to 3.5.29.
CVE-2021-24649 is a vulnerability in the WP User Frontend WordPress plugin where the registration form's urhidden argument is used to create user accounts with a role, which can be exploited by attackers who have access to the AUTH_KEY and AUTH_SALT constant values.
To fix CVE-2021-24649, update the WP User Frontend WordPress plugin to version 3.5.29 or higher.