vendor:
Extra User Details
by:
Panagiotis Vagenas
N/A
CVSS
N/A
Privilege Escalation
Unknown
CWE
Product Name: Extra User Details
Affected Version From: 2000.4.2
Affected Version To: 2000.4.2
Patch Exists: NO
Related CWE: Unknown
CPE: Unknown
Platforms Tested: WordPress
2016
Extra User Details [Privilege Escalation]
Extra User Details plugin for WordPress suffers from a Privilege Escalation vulnerability. The plugin hooks the eud_update_ExtraFields function to profile_update WordPress action. This function doesn't properly check user capabilities and updates all meta information passed to post data. An attacker can exploit this misbehavior to gain administrative privileges.
Mitigation:
Unknown