CVE-2024-54363 CRITICAL

CVE-2024-54363: WordPress Wp NssUser Register plugin <= 1.0.0 - Privilege Escalation vulnerability

Vendor Saiful.total
Product Wp NssUser Register
Weakness CWE-266
Published December 16, 2024
Last update April 28, 2026

CVSS base score

9.8/10
Attack vector Network
Attack complexity Low
Privileges required None
User interaction None
Confidentiality High
Integrity High

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

What the vulnerability does

01Description

Incorrect Privilege Assignment vulnerability in saiful.total Wp NssUser Register wp-nssuser-register allows Privilege Escalation.This issue affects Wp NssUser Register: from n/a through <= 1.0.0.

Explanation of Vulnerability in Simple Terms

02Summary

Wp NssUser Register versions 1.0.0 and earlier contain an improper access control vulnerability that allows unauthenticated attackers to read, modify, or delete sensitive data and execute code on the site without any user interaction. The vulnerability affects all network-accessible instances of the plugin with default configuration. Site administrators should update immediately to a patched version.

What an attacker can do

03Attacker Capabilities

Read, modify, or delete site data and run code on the site without logging in.

Potential impact on your site

04Site Impact

Attackers can compromise user accounts, steal data, modify content, or take over the site entirely.

Conditions required to exploit

05Prerequisites

Network access to the site; no authentication or user interaction required.

Key dates

06Disclosure timeline

December 16, 2024 CVE published
April 28, 2026 Record updated

Related vulnerabilities

08Related CVE