Unrated severityNVD Advisory· Published Sep 20, 2024· Updated Apr 8, 2026
Webo-facto <= 1.40 - Unauthenticated Privilege Escalation
CVE-2024-8853
Description
The Webo-facto plugin for WordPress is vulnerable to privilege escalation in versions up to, and including, 1.40 due to insufficient restriction on the 'doSsoAuthentification' function. This makes it possible for unauthenticated attackers to make themselves administrators by registering with a username that contains '-wfuser'.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3- Range: <=1.40
- jeremieglotin/Webo-factov5Range: 0
Patches
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
3News mentions
0No linked articles in our index yet.