vendor:
Pie Register
by:
Lotfi13-DZ
7.5
CVSS
HIGH
Admin Privilege Escalation
284
CWE
Product Name: Pie Register
Affected Version From: <= 3.7.1.4
Affected Version To: 3.7.1.4
Patch Exists: NO
Related CWE:
CPE: a:wordpress:pie_register:3.7.1.4
Platforms Tested: Ubuntu
2021
WordPress Plugin Pie Register 3.7.1.4 – Admin Privilege Escalation (Unauthenticated)
The vulnerability allows an unauthenticated attacker to escalate their privileges and gain administrative access. By sending a specially crafted request, the attacker can retrieve the authentication cookies for the admin user.
Mitigation:
Update to the latest version of the plugin or apply the patch provided by the vendor.