CVE-2024-54365 HIGH

CVE-2024-54365: WordPress KH Easy User Settings plugin <= 1.0.0 - Privilege Escalation vulnerability

Vendor Knowhalim
Product KH Easy User Settings
Weakness CWE-266
Published December 16, 2024
Last update April 28, 2026

CVSS base score

8.8/10
Attack vector Network
Attack complexity Low
Privileges required Low
User interaction None
Confidentiality High
Integrity High

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

What the vulnerability does

01Description

Incorrect Privilege Assignment vulnerability in Knowhalim KH Easy User Settings kh-easy-user-settings allows Privilege Escalation.This issue affects KH Easy User Settings: from n/a through <= 1.0.0.

Explanation of Vulnerability in Simple Terms

02Summary

KH Easy User Settings versions 1.0.0 and earlier contain an improper access control vulnerability. An authenticated user with low privileges can read, modify, or delete sensitive data and settings. The vulnerability requires valid login credentials but no additional user interaction. All confidentiality, integrity, and availability protections are compromised for affected installations.

What an attacker can do

03Attacker Capabilities

Read, modify, or delete sensitive user data and site settings with a low-privilege account.

Potential impact on your site

04Site Impact

Any registered user can access and alter critical settings and user data, potentially compromising site security and user privacy.

Conditions required to exploit

05Prerequisites

Valid login credentials with low-level user privileges; network access to the site.

Key dates

06Disclosure timeline

December 16, 2024 CVE published
April 28, 2026 Record updated

Related vulnerabilities

08Related CVE