CVE-2024-6411: ProfileGrid – User Profiles, Groups and Communities <= 5.8.9 - Authenticated (Subscriber+) Authorization Bypass to Privilege Escalation
The ProfileGrid – User Profiles, Groups and Communities plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including, 5.8.9. This is due to a lack of validation on user-supplied data in the 'pmuploadimage' AJAX action. This makes it possible for authenticated attackers, with Subscriber-level access and above, to update their user capabilities to Administrator.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
wordpress/ProfileGrid – User Profiles, Groups and Communitiesto a version that resolves this vulnerability.Fixed in 5.8.9 - Compensating control
Mitigate the privilege escalation by restricting authenticated (Subscriber+) access to the WordPress endpoint handling the 'pm_upload_image' AJAX action so only trusted users can reach it.
Event History
Frequently Asked Questions
What is the severity of CVE-2024-6411?
CVE-2024-6411 has a high severity due to its privilege escalation capability in the vulnerable plugin.
How do I fix CVE-2024-6411?
To fix CVE-2024-6411, update the ProfileGrid plugin to version 5.9.0 or later.
What versions are affected by CVE-2024-6411?
CVE-2024-6411 affects all versions of the ProfileGrid plugin up to and including 5.8.9.
What is the root cause of CVE-2024-6411?
The root cause of CVE-2024-6411 is a lack of validation on user-supplied data in the 'pm_upload_image' AJAX action.
Can CVE-2024-6411 be exploited remotely?
Yes, CVE-2024-6411 can be exploited remotely due to its AJAX action vulnerability, allowing unauthorized privilege escalation.