CVE-2024-43153 CRITICAL

CVE-2024-43153: WordPress Woffice theme <= 5.4.10 - Unauthenticated Privilege Escalation vulnerability

Vendor Wofficeio
Product Woffice
Weakness CWE-266
Published August 13, 2024
Last update April 28, 2026

CVSS base score

9.8/10
Attack vector Network
Attack complexity Low
Privileges required None
User interaction None
Confidentiality High
Integrity High

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

What the vulnerability does

01Description

Incorrect Privilege Assignment vulnerability in WofficeIO Woffice woffice.This issue affects Woffice: from n/a through <= 5.4.10.

Explanation of Vulnerability in Simple Terms

02Summary

Woffice versions up to 5.4.10 contain a privilege escalation vulnerability that allows unauthenticated attackers to gain full control of the application. The vulnerability stems from improper access control that fails to enforce authorization checks on sensitive operations. An attacker can read, modify, or delete any data and run their own code on the server without needing valid credentials.

What an attacker can do

03Attacker Capabilities

Run code on the server, read all data, modify or delete files, and take full control of the application.

Potential impact on your site

04Site Impact

Complete compromise of the Woffice installation and any data it stores; attackers can impersonate users and modify site content.

Conditions required to exploit

05Prerequisites

Network access only; no authentication or user interaction required.

Key dates

06Disclosure timeline

August 13, 2024 CVE published
April 28, 2026 Record updated

Related vulnerabilities

08Related CVE