Medialibs Webo-facto 1.28 for WordPress

CPE Details

Medialibs Webo-facto 1.28 for WordPress
1.28
2024-09-25
19h19 +00:00
2024-09-25
19h19 +00:00
Alerte pour un CPE
Stay informed of any changes for a specific CPE.
Notifications manage

CPE Name: cpe:2.3:a:medialibs:webo-facto:1.28:*:*:*:*:wordpress:*:*

Informations

Vendor

medialibs

Product

webo-facto

Version

1.28

Target Software

wordpress

Related CVE

Open and find in CVE List

CVE ID Published Description Score Severity
CVE-2024-8853 2024-09-20 07h33 +00:00 The Webo-facto plugin for WordPress is vulnerable to privilege escalation in versions up to, and including, 1.40 due to insufficient restriction on the 'doSsoAuthentification' function. This makes it possible for unauthenticated attackers to make themselves administrators by registering with a username that contains '-wfuser'.
9.8
Critical