ConvertPlug <= 3.4.2 - Unauthenticated Administrator Creation

2019-05-29 00:00
Mikey Veenstra

Strategic Overview

Status
Patched in 3.4.3
Affected PluginConvertPlus
Affected Version< 3.4.3
CVSS9.8Critical
CVEN/A
View all ConvertPlus vulnerabilities

Vulnerability Overview

The ConvertPlug plugin for WordPress is vulnerable to Unauthenticated Administrator Creation in versions up to, and including, 3.4.2. This is due to insufficient validation on role selection during user registeration. This makes it possible for unauthenticated attackers to register as administrators on vulnerable sites.

Technical Analysis

REMEDIATION: Update to version 3.4.3, or a newer patched version --- IDENTIFIER: CWE-266 (Incorrect Privilege Assignment) A product incorrectly assigns a privilege to a particular actor, creating an unintended sphere of control for that actor.

External References

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C