The DHVC Form plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including, 2.4.7. This is due to the plugin allowing a user to supply the 'role' field when registering. This makes it possible for unauthenticated attackers to register as an administrator on sites.
References
Configurations
History
06 Mar 2025, 16:36
Type | Values Removed | Values Added |
---|---|---|
CPE | cpe:2.3:a:sitesao:dhvc_form:*:*:*:*:*:wordpress:*:* | |
CWE | CWE-269 | |
References | () https://codecanyon.net/item/dhvc-form-wordpress-form-for-visual-composer/8326593 - Product | |
References | () https://www.wordfence.com/threat-intel/vulnerabilities/id/e4d51a0c-c625-4732-b345-df02971fbffa?source=cve - Third Party Advisory | |
Summary |
|
|
First Time |
Sitesao
Sitesao dhvc Form |
28 Feb 2025, 09:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2025-02-28 09:15
Updated : 2025-03-06 16:36
NVD link : CVE-2024-8420
Mitre link : CVE-2024-8420
CVE.ORG link : CVE-2024-8420
JSON object : View
Products Affected
sitesao
- dhvc_form