CVE Vulnerabilities

CVE-2024-8420

Incorrect Privilege Assignment

Published: Feb 28, 2025 | Modified: Mar 06, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

The DHVC Form plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including, 2.4.7. This is due to the plugin allowing a user to supply the role field when registering. This makes it possible for unauthenticated attackers to register as an administrator on sites.

Weakness

A product incorrectly assigns a privilege to a particular actor, creating an unintended sphere of control for that actor.

Affected Software

NameVendorStart VersionEnd Version
Dhvc_formSitesao*2.4.8 (excluding)

Potential Mitigations

References