CVE-2024-2172

Malware Scanner <= 4.7.2 and Web Application Firewall <= 2.1.1 - Unauthenticated Privilege Escalation

2024-03-13 00:00
Stiofan

Strategic Overview

Status
Patched in 2.1.2
Affected Version
<= 2.1.1
CVSS
9.8Critical
Weakness type
CWE-304 · Missing Critical Step in Authentication
CVE
CVE-2024-2172
View all Web Application Firewall – website security vulnerabilities

At a glance

CVE-2024-2172 is a critical-severity Missing Critical Step in Authentication vulnerability in the Web Application Firewall WordPress plugin, affecting versions <= 2.1.1. It carries a CVSS score of 9.8 (reachable over the network; low attack complexity; high confidentiality, integrity, availability impact). Exploitation requires no authentication. The issue is fixed in version 2.1.2; sites on affected versions should update now. Disclosed March 2024, reported by Stiofan.

Vulnerability Overview

The Malware Scanner plugin and the Web Application Firewall plugin for WordPress (both by MiniOrange) are vulnerable to privilege escalation due to a missing capability check on the mo_wpns_init() function in all versions up to, and including, 4.7.2 (for Malware Scanner) and 2.1.1 (for Web Application Firewall). This makes it possible for unauthenticated attackers to escalate their privileges to that of an administrator.

Technical Analysis

The vector marks this flaw as remotely reachable over the network, with low attack complexity — no special timing or configuration is needed, and no privileges on the target site, and no interaction from a victim user. A successful exploit has high impact on confidentiality, integrity, availability — full site compromise territory.

CWE-304: Missing Critical Step in Authentication

The product implements an authentication technique, but it skips a step that weakens the technique.

Remediation

Update to version 2.1.2, or a newer patched version

How does WordSec protect against this?

This one needs no account at all, which puts it outside what login hardening can reach; WordSec's login security narrows the account-level paths around it, and the firewall is what inspects the request itself. None of that substitutes for the fix: Web Application Firewall 2.1.2 closes this, and updating the plugin is the step that ends it.

  • Login Security
  • Alerts

External References

Related records

Other vulnerabilities in Web Application Firewall – website security

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C