CVE-2024-3828: Spectra Pro <= 1.1.5 - Authenticated (Author+) Privilege Escalation
The Spectra Pro plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including, 1.1.5. This is due to the plugin allowing lower-privileged users to create registration forms and set the default role to administrator This makes it possible for authenticated attackers, with author-level access and above, to create administrator-level accounts.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-3828?
CVE-2024-3828 is considered a high severity vulnerability due to its potential for privilege escalation.
How do I fix CVE-2024-3828?
To fix CVE-2024-3828, update the Spectra Pro plugin to version 1.1.6 or later.
Who is affected by CVE-2024-3828?
All users of the Spectra Pro plugin for WordPress running versions up to 1.1.5 are affected by CVE-2024-3828.
What types of exploitation are possible with CVE-2024-3828?
CVE-2024-3828 allows lower-privileged users to create registration forms that can assign administrator roles, leading to potential full site takeover.
What versions of the Spectra Pro plugin are vulnerable to CVE-2024-3828?
All versions of the Spectra Pro plugin up to and including version 1.1.5 are vulnerable to CVE-2024-3828.