CVE-2024-8246: Post Form – Registration Form – Profile Form for User Profiles – Frontend Content Forms for User Submissions (UGC) <= 2.8.11 - Authenticated (Contributor+) Privilege Escalation
The Post Form – Registration Form – Profile Form for User Profiles – Frontend Content Forms for User Submissions (UGC) plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including, 2.8.11. This is due to plugin not properly restricting what users have access to set the default role on registration forms. This makes it possible for authenticated attackers, with contributor-level access and above, to create a registration form with a custom role that allows them to register as administrators.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2024-8246?
CVE-2024-8246 has been rated as a high-severity vulnerability due to its potential for privilege escalation.
How do I fix CVE-2024-8246?
To mitigate CVE-2024-8246, users should update the BuddyForms plugin to version 2.8.12 or higher.
What versions are affected by CVE-2024-8246?
CVE-2024-8246 affects all versions of the BuddyForms plugin up to and including 2.8.11.
What type of vulnerability is CVE-2024-8246?
CVE-2024-8246 is a privilege escalation vulnerability that allows unauthorized users to gain elevated access rights.
Who is impacted by CVE-2024-8246?
Website owners using the BuddyForms plugin for WordPress are impacted by CVE-2024-8246, particularly those on affected versions.