Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-48951 | The The Ultimate WordPress Toolkit – WP Extended plugin for WordPress is vulnerable to unauthorized modification of user names due to a missing capability check on the wpext_change_admin_name() function in all versions up to, and including, 3.0.8. This makes it possible for authenticated attackers, with Subscriber-level access and above, to change an admin's username to a username of their liking as long as the default 'admin' was used. |
Fri, 06 Sep 2024 16:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Wpextended
Wpextended wp Extended |
|
| CPEs | cpe:2.3:a:wpextended:wp_extended:*:*:*:*:*:wordpress:*:* | |
| Vendors & Products |
Wpextended
Wpextended wp Extended |
Wed, 04 Sep 2024 14:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 04 Sep 2024 07:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The The Ultimate WordPress Toolkit – WP Extended plugin for WordPress is vulnerable to unauthorized modification of user names due to a missing capability check on the wpext_change_admin_name() function in all versions up to, and including, 3.0.8. This makes it possible for authenticated attackers, with Subscriber-level access and above, to change an admin's username to a username of their liking as long as the default 'admin' was used. | |
| Title | The Ultimate WordPress Toolkit – WP Extended <= 3.0.8 - Missing Authorization to Admin Username Change | |
| Weaknesses | CWE-862 | |
| References |
|
|
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: Wordfence
Published:
Updated: 2026-04-08T17:32:58.158Z
Reserved: 2024-08-23T14:40:34.473Z
Link: CVE-2024-8121
Updated: 2024-09-04T13:16:26.244Z
Status : Analyzed
Published: 2024-09-04T07:15:04.887
Modified: 2024-09-06T16:20:59.767
Link: CVE-2024-8121
No data.
OpenCVE Enrichment
No data.
EUVD