CVE-2024-7291: JetFormBuilder <= 3.3.4.1 - Authenticated (Administrator+) Privilege Escalation
The JetFormBuilder plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including, 3.3.4.1. This is due to improper restriction on user meta fields. This makes it possible for authenticated attackers, with administrator-level and above permissions, to register as super-admins on the sites configured as multi-sites.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-7291?
The severity of CVE-2024-7291 is considered high due to its capability to allow privilege escalation for authenticated attackers.
How do I fix CVE-2024-7291?
To fix CVE-2024-7291, users should update the JetFormBuilder plugin to the latest version that is above 3.3.4.1.
Who is affected by CVE-2024-7291?
CVE-2024-7291 affects users of the JetFormBuilder plugin for WordPress who are running versions up to and including 3.3.4.1.
What causes the vulnerability CVE-2024-7291?
CVE-2024-7291 is caused by improper restrictions on user meta fields within the JetFormBuilder plugin.
Can unauthenticated users exploit CVE-2024-7291?
No, only authenticated users with administrator-level and above permissions can exploit CVE-2024-7291.