CVE-2024-8853 - Webo-Facto WordPress Privilege Escalation

2 months ago 30
ARTICLE AD BOX
CVE ID : CVE-2024-8853
Published : Sept. 20, 2024, 8:15 a.m. | 24 minutes ago
Description : The Webo-facto plugin for WordPress is vulnerable to privilege escalation in versions up to, and including, 1.40 due to insufficient restriction on the 'doSsoAuthentification' function. This makes it possible for unauthenticated attackers to make themselves administrators by registering with a username that contains '-wfuser'.
Severity: 9.8 | CRITICAL
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
Read Entire Article