CVE-2024-2172: Malware Scanner <= 4.7.2 and Web Application Firewall <= 2.1.1 - Unauthenticated Privilege Escalation
The Malware Scanner plugin and the Web Application Firewall plugin for WordPress (both by MiniOrange) are vulnerable to privilege escalation due to a missing capability check on the mowpnsinit() function in all versions up to, and including, 4.7.2 (for Malware Scanner) and 2.1.1 (for Web Application Firewall). This makes it possible for unauthenticated attackers to escalate their privileges to that of an administrator.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-2172?
CVE-2024-2172 is classified as a high-severity vulnerability due to its potential for privilege escalation.
How do I fix CVE-2024-2172?
To fix CVE-2024-2172, update the MiniOrange Malware Scanner plugin to version 4.7.3 or later, and the Web Application Firewall plugin to version 2.1.2 or later.
Which versions are affected by CVE-2024-2172?
CVE-2024-2172 affects MiniOrange Malware Scanner versions up to 4.7.2 and Web Application Firewall versions up to 2.1.1.
What is the impact of CVE-2024-2172?
The impact of CVE-2024-2172 is that it allows authenticated users to escalate their privileges, potentially leading to full control of the WordPress site.
Who is the vendor for the vulnerable plugins in CVE-2024-2172?
The vendor for the vulnerable plugins in CVE-2024-2172 is MiniOrange.