ZeroHour

CVE-2024-8420

CVSS 3.1
9.8 critical
EPSS
<1%p43
Published
()
Modified
Description

The DHVC Form plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including, 2.4.7. This is due to the plugin allowing a user to supply the 'role' field when registering. This makes it possible for unauthenticated attackers to register as an administrator on sites.

Vendors
sitesao
Products
dhvc form
Ecosystems
WordPress
Weakness
CWE-266, CWE-269
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news