What the vulnerability does
01Description
Improper Privilege Management vulnerability in WPForms, LLC. WPForms User Registration allows Privilege Escalation.This issue affects WPForms User Registration: from n/a through 2.1.0.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H
What the vulnerability does
Improper Privilege Management vulnerability in WPForms, LLC. WPForms User Registration allows Privilege Escalation.This issue affects WPForms User Registration: from n/a through 2.1.0.
Explanation of Vulnerability in Simple Terms
WPForms User Registration versions up to 2.1.0 contain a privilege management flaw that allows authenticated users with low privileges to perform actions reserved for higher-privilege roles. An attacker must be logged in and trick a user into clicking a malicious link. This can result in unauthorized data access, modification, or site disruption.
What an attacker can do
Read, modify, or delete sensitive data and site settings beyond their assigned role.
Potential impact on your site
Unauthorized users can escalate their capabilities to perform admin-level actions on registration forms and user data.
Conditions required to exploit
Attacker must be logged in as a low-privilege user and the victim must click a link or visit a page.
Key dates
External resources
Related vulnerabilities