CVE-2024-9265: Echo RSS Feed Post Generator <= 5.4.6 - Unauthenticated Privilege Escalation
The Echo RSS Feed Post Generator plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including, 5.4.6. This is due to the plugin not properly restricting the roles that can set during registration through the echocheckpostheadersent() function. This makes it possible for unauthenticated attackers to register as an administrator.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-9265?
CVE-2024-9265 is classified as a privilege escalation vulnerability.
How do I fix CVE-2024-9265?
To fix CVE-2024-9265, update the Echo RSS Feed Post Generator plugin to version 5.4.7 or higher.
Which versions of the Echo RSS Feed Post Generator plugin are affected by CVE-2024-9265?
CVE-2024-9265 affects all versions of the Echo RSS Feed Post Generator plugin up to and including version 5.4.6.
What is the cause of CVE-2024-9265?
CVE-2024-9265 is caused by improper role restrictions during registration in the echo_check_post_header_sent() function.
Who is impacted by CVE-2024-9265?
Users of the Echo RSS Feed Post Generator plugin for WordPress running affected versions are at risk due to CVE-2024-9265.