CVE-2024-12594 Information
Description
The Custom Login Page Styler – Login Protected Private Site Change wp-admin login url WordPress login logo Temporary admin login access Rename login Login customizer Hide wp-login – Limit Login Attempts – Locked Site plugin for WordPress is vulnerable to privilege escalation due to a missing capability check on the ’lps_generate_temp_access_url’ AJAX action in all versions up to and including 7.1.1. This makes it possible for authenticated attackers with Subscriber-level access and above to login as other users such as subscribers.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Reference
https://plugins.trac.wordpress.org/changeset?sfp_email=&sfph_mail=&reponame=&old=3208192%40login-page-styler&new=3208192%40login-page-styler&sfp_email=&sfph_mail= https://www.wordfence.com/threat-intel/vulnerabilities/id/8e50c519-7d79-4270-92e8-75e54bb08cff?source=cve The Custom Login Page Styler – Login Protected Private Site
Change wp-admin login url
WordPress login logo
Temporary admin login access
Rename login
Login customizer Hide wp-login – Limit Login Attempts – Locked Site plugin for WordPress is vulnerable to privilege escalation due to a missing capability check on the ’lps_generate_temp_access_url' AJAX action in all versions up to and including 7.1.1. This makes it possible for authenticated attackers with Subscriber-level access and above to login as other users such as subscribers.
Attack Complexity
LOW
Privileges Required
LOW
User Interaction Required
LOW
Scope
NONE
Confidentiality Impact
UNCHANGED
Integrity Impact
HIGH
Availability Impact
HIGH
Base Score
HIGH
Base Severity
8.8
Share on: