VYPR
High severity7.2NVD Advisory· Published Oct 10, 2024· Updated Jun 17, 2026No known patch

CVE-2024-9519

CVE-2024-9519

Description

The UserPlus plugin for WordPress is vulnerable to unauthorized modification of data due to an improper capability check on the 'save_metabox_form' function in versions up to, and including, 2.0. This makes it possible for authenticated attackers, with editor-level permissions or above, to update the registration form role to administrator, which leads to privilege escalation.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

2
  • cpe:2.3:a:wpuserplus:userplus:*:*:*:*:*:wordpress:*:*
    Range: <=2.0
  • userplus/User registration & user profile – UserPlusv5
    Range: 0

Patches

Vulnerability mechanics

References

2

News mentions

0

No linked articles in our index yet.