ConvertPlug <= 3.4.2 - Unauthenticated Administrator Creation
2019-05-29 00:00
Mikey VeenstraStrategic Overview
Vulnerability Overview
The ConvertPlug plugin for WordPress is vulnerable to Unauthenticated Administrator Creation in versions up to, and including, 3.4.2. This is due to insufficient validation on role selection during user registeration. This makes it possible for unauthenticated attackers to register as administrators on vulnerable sites.
Technical Analysis
REMEDIATION: Update to version 3.4.3, or a newer patched version --- IDENTIFIER: CWE-266 (Incorrect Privilege Assignment) A product incorrectly assigns a privilege to a particular actor, creating an unintended sphere of control for that actor.
External References
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C