CVE-2024-9522

T

he WP Users Masquerade plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 2.0.0. This is due to incorrect authentication and capability checking in the 'ajax_masq_login' function. This makes it possible for authenticated attackers, with subscriber-level permissions and above, to log in as any existing user on the site, such as an administrator.

Configurations

Configuration 1 (hide)

cpe:2.3:a:lagunaisw:wp_users_masquerade:*:*:*:*:*:wordpress:*:*

History

15 Oct 2024, 14:27

Type Values Removed Values Added
First Time Lagunaisw
Lagunaisw wp Users Masquerade
CWE CWE-306
CPE cpe:2.3:a:lagunaisw:wp_users_masquerade:*:*:*:*:*:wordpress:*:*
References () https://plugins.trac.wordpress.org/browser/wp-users-masquerade/trunk/masquerade.php?rev=1703860#L162 - () https://plugins.trac.wordpress.org/browser/wp-users-masquerade/trunk/masquerade.php?rev=1703860#L162 - Product
References () https://www.wordfence.com/threat-intel/vulnerabilities/id/4a4f0909-76f6-4d27-87b1-f6cd5f5cbbb7?source=cve - () https://www.wordfence.com/threat-intel/vulnerabilities/id/4a4f0909-76f6-4d27-87b1-f6cd5f5cbbb7?source=cve - Third Party Advisory

10 Oct 2024, 12:51

Type Values Removed Values Added
Summary
  • (es) El complemento WP Users Masquerade para WordPress es vulnerable a la omisión de autenticación en versiones hasta la 2.0.0 incluida. Esto se debe a una verificación de autenticación y capacidad incorrecta en la función 'ajax_masq_login'. Esto hace posible que atacantes autenticados, con permisos de nivel de suscriptor y superiores, inicien sesión como cualquier usuario existente en el sitio, como un administrador.

10 Oct 2024, 02:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-10-10 02:15

Updated : 2024-10-15 14:27


NVD link : CVE-2024-9522

Mitre link : CVE-2024-9522

CVE.ORG link : CVE-2024-9522


JSON object : View

Products Affected
CWE
CWE-306

Missing Authentication for Critical Function

CWE-288

Authentication Bypass Using an Alternate Path or Channel