Medialibs Webo-facto 1.25 for WordPress

CPE Details

Medialibs Webo-facto 1.25 for WordPress
1.25
2024-09-25
19h19 +00:00
2024-09-25
19h19 +00:00
Alerte pour un CPE
Restez informé de toutes modifications pour un CPE spécifique.
Gestion des notifications

CPE Name: cpe:2.3:a:medialibs:webo-facto:1.25:*:*:*:*:wordpress:*:*

Informations

Vendor

medialibs

Product

webo-facto

Version

1.25

Target Software

wordpress

Related CVE

Open and find in CVE List

CVE ID Publié Description Score Gravité
CVE-2024-8853 2024-09-20 07h33 +00:00 The Webo-facto plugin for WordPress is vulnerable to privilege escalation in versions up to, and including, 1.40 due to insufficient restriction on the 'doSsoAuthentification' function. This makes it possible for unauthenticated attackers to make themselves administrators by registering with a username that contains '-wfuser'.
9.8
Critique