VYPR
Critical severity9.8NVD Advisory· Published Sep 20, 2024· Updated Jun 17, 2026

CVE-2024-8853

CVE-2024-8853

Description

The Webo-facto plugin for WordPress is vulnerable to privilege escalation in versions up to, and including, 1.40 due to insufficient restriction on the 'doSsoAuthentification' function. This makes it possible for unauthenticated attackers to make themselves administrators by registering with a username that contains '-wfuser'.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

4
  • cpe:2.3:a:medialibs:webo-facto:*:*:*:*:*:wordpress:*:*
    Range: <1.41
  • WordPress/Webo-factollm-fuzzy2 versions
    <=1.40+ 1 more
    • (no CPE)range: <=1.40
    • (no CPE)
  • jeremieglotin/Webo-factov5
    Range: 0

Patches

Vulnerability mechanics

References

3

News mentions

0

No linked articles in our index yet.