Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-49168 | The ForumWP – Forum & Discussion Board Plugin plugin for WordPress is vulnerable to Privilege Escalation via Insecure Direct Object Reference in all versions up to, and including, 2.0.2 via the submit_form_handler due to missing validation on the 'user_id' user controlled key. This makes it possible for authenticated attackers, with subscriber-level access and above, to change the email address of administrative user accounts which can then be leveraged to reset the administrative users password and gain access to their account. |
Wed, 08 Apr 2026 18:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
Thu, 26 Sep 2024 22:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Ultimatemember
Ultimatemember forumwp |
|
| CPEs | cpe:2.3:a:ultimatemember:forumwp:*:*:*:*:*:wordpress:*:* | |
| Vendors & Products |
Ultimatemember
Ultimatemember forumwp |
Fri, 06 Sep 2024 15:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Forumwp
Forumwp forumwp |
|
| CPEs | cpe:2.3:a:forumwp:forumwp:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Forumwp
Forumwp forumwp |
|
| Metrics |
ssvc
|
Fri, 06 Sep 2024 14:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The ForumWP – Forum & Discussion Board Plugin plugin for WordPress is vulnerable to Privilege Escalation via Insecure Direct Object Reference in all versions up to, and including, 2.0.2 via the submit_form_handler due to missing validation on the 'user_id' user controlled key. This makes it possible for authenticated attackers, with subscriber-level access and above, to change the email address of administrative user accounts which can then be leveraged to reset the administrative users password and gain access to their account. | |
| Title | ForumWP – Forum & Discussion Board Plugin <= 2.0.2 - Insecure Direct Object Reference to Authenticated (Subscriber+) Privilege Escalation via Account Takeover | |
| Weaknesses | CWE-639 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: Wordfence
Published:
Updated: 2026-04-08T17:17:12.624Z
Reserved: 2024-09-04T15:06:42.231Z
Link: CVE-2024-8428
Updated: 2024-09-06T14:11:36.672Z
Status : Modified
Published: 2024-09-06T14:15:13.823
Modified: 2026-04-08T19:22:24.803
Link: CVE-2024-8428
No data.
OpenCVE Enrichment
No data.
EUVD