Critical severity9.8NVD Advisory· Published Sep 20, 2024· Updated Jun 17, 2026
CVE-2024-8853
CVE-2024-8853
Description
The Webo-facto plugin for WordPress is vulnerable to privilege escalation in versions up to, and including, 1.40 due to insufficient restriction on the 'doSsoAuthentification' function. This makes it possible for unauthenticated attackers to make themselves administrators by registering with a username that contains '-wfuser'.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
4<=1.40+ 1 more
- (no CPE)range: <=1.40
- (no CPE)
- jeremieglotin/Webo-factov5Range: 0
Patches
Vulnerability mechanics
References
3News mentions
0No linked articles in our index yet.