CVE-2024-8121

The The Ultimate WordPress Toolkit – WP Extended plugin for WordPress is vulnerable to unauthorized modification of user names due to a missing capability check on the wpext_change_admin_name() function in all versions up to, and including, 3.0.8. This makes it possible for authenticated attackers, with Subscriber-level access and above, to change an admin's username to a username of their liking as long as the default 'admin' was used.
Configurations

Configuration 1 (hide)

cpe:2.3:a:wpextended:wp_extended:*:*:*:*:*:wordpress:*:*

History

No history.

Information

Published : 2024-09-04 07:15

Updated : 2024-09-06 16:20


NVD link : CVE-2024-8121

Mitre link : CVE-2024-8121

CVE.ORG link : CVE-2024-8121


JSON object : View

Products Affected

wpextended

  • wp_extended
CWE
CWE-862

Missing Authorization