CVE-2024-9235
Mapster
CVE-2024-9235 affects the Mapster WP Maps plugin for WordPress, enabling privilege escalation. Authenticated attackers with contributor access can modify WordPress options due to a lack of capability checks in the mapster_wp_maps_set_option_from_js()
function up to version 1.5.0. The vulnerability allows attackers to change the default user role to administrator and enable user registration, granting them admin access. Although the CVSS score is 8.8, the SOCRadar Vulnerability Risk Score (SVRS) of 77 suggests it is nearing critical severity. This means exploitation may be imminent. Immediate patching is advised to prevent unauthorized access and maintain site security. The vulnerability poses a high risk due to the potential for complete site takeover.
Indicators of Compromise
Exploits
News
Social Media
Affected Software
References
CWE Details
CVE Radar
Real-time CVE Intelligence & Vulnerability Management Platform
CVE Radar provides comprehensive vulnerability intelligence by monitoring CVE databases, security advisories, and threat feeds. Get instant updates on new vulnerabilities, exploit details, and mitigation strategies specific to your assets.