Bstone Demo Importer <= 1.0.1 - Missing Authorization to Authenticated (Subscriber+) Privilege Escalation

2024-10-25 00:00
stealthcopter

Strategic Overview

Status
Unpatched
Affected PluginBstone Demo Importer
Affected Version<= 1.0.1
CVSS8.8High
CVECVE-2024-50481
View all Bstone Demo Importer vulnerabilities

Vulnerability Overview

The Bstone Demo Importer plugin for WordPress is vulnerable to privilege escalation due to a missing capability check on the reset_wizard_actions() function in all versions up to, and including, 1.0.1. This makes it possible for authenticated attackers, with Subscriber-level access and above, to reset the WordPress site which will automatically log them in as the site administrator.

Technical Analysis

REMEDIATION: No known patch available. Please review the vulnerability's details in depth and employ mitigations based on your organization's risk tolerance. It may be best to uninstall the affected software and find a replacement. --- IDENTIFIER: CWE-862 (Missing Authorization) The product does not perform an authorization check when an actor attempts to access a resource or perform an action.

External References

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C