WordPress Plugin Vulnerabilities

Import Export WordPress Users < 1.3.9 - Authenticated Arbitrary User Creation

Description

"The flaw allowed anybody with subscriber-level access or above to import new users via a CSV file, including administrative-level users" providing subscriber-level users and above with the ability to escalate their privileges.

Proof of Concept

Affects Plugins

References

Classification

Miscellaneous

Original Researcher
Chloe Chamberland
Submitter
Chloe Chamberland
Submitter website
Submitter twitter
Verified
No

Timeline

Publicly Published
2020-03-11 (about 6 years ago)
Added
2020-03-11 (about 6 years ago)
Last Updated
2020-04-24 (about 6 years ago)

Other