WordPress Plugin Vulnerabilities

ProfilePress 3.0 - 3.1.3 - Unauthenticated Privilege Escalation

Description

The user registration functionality of the plugin allowed arbitrary user meta to be supplied, including wp_capabilities, during registration which made it possible for users to register as an administrator.

Proof of Concept

Affects Plugins

Fixed in 3.1.4

References

Classification

Miscellaneous

Original Researcher
Chloe Chamberland
Submitter
Chloe Chamberland
Submitter website
Submitter twitter
Verified
No

Timeline

Publicly Published
2021-06-28 (about 4 years ago)
Added
2021-06-28 (about 4 years ago)
Last Updated
2022-01-17 (about 4 years ago)

Other