The PowerPack Pro for Elementor plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including, 2.10.17. This is due to the plugin not restricting low privileged users from setting a default role for a registration form. This makes it possible for authenticated attackers, with contributor-level access and above, to create a registration form with administrator set as the default role and then register as an administrator.
References
Link | Resource |
---|---|
https://powerpackelements.com/change-logs/ | Release Notes |
https://www.wordfence.com/threat-intel/vulnerabilities/id/249ccc77-0daf-41bc-b5c5-991bf17d645d?source=cve | Third Party Advisory |
Configurations
History
23 Jul 2024, 19:39
Type | Values Removed | Values Added |
---|---|---|
Summary |
|
|
References | () https://powerpackelements.com/change-logs/ - Release Notes | |
References | () https://www.wordfence.com/threat-intel/vulnerabilities/id/249ccc77-0daf-41bc-b5c5-991bf17d645d?source=cve - Third Party Advisory | |
CPE | cpe:2.3:a:ideabox:powerpack_addons_for_elementor:*:*:*:*:*:wordpress:*:* | |
First Time |
Ideabox powerpack Addons For Elementor
Ideabox |
|
CWE | CWE-732 |
08 Jun 2024, 05:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2024-06-08 05:15
Updated : 2024-07-23 19:39
NVD link : CVE-2024-3668
Mitre link : CVE-2024-3668
CVE.ORG link : CVE-2024-3668
JSON object : View
Products Affected
ideabox
- powerpack_addons_for_elementor
CWE
CWE-732
Incorrect Permission Assignment for Critical Resource