Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-49983 | The UserPlus plugin for WordPress is vulnerable to unauthorized access, modification, and loss of data due to a missing capability check on multiple functions in all versions up to, and including, 2.0. This makes it possible for authenticated attackers with subscriber-level permissions or above, to add, modify, or delete user meta and plugin options. |
Tue, 15 Oct 2024 15:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Wpuserplus
Wpuserplus userplus |
|
| CPEs | cpe:2.3:a:wpuserplus:userplus:*:*:*:*:*:wordpress:*:* | |
| Vendors & Products |
Wpuserplus
Wpuserplus userplus |
Thu, 10 Oct 2024 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 10 Oct 2024 02:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The UserPlus plugin for WordPress is vulnerable to unauthorized access, modification, and loss of data due to a missing capability check on multiple functions in all versions up to, and including, 2.0. This makes it possible for authenticated attackers with subscriber-level permissions or above, to add, modify, or delete user meta and plugin options. | |
| Title | UserPlus <= 2.0 - Missing Authorization via Multiple Functions | |
| Weaknesses | CWE-862 | |
| References |
|
|
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: Wordfence
Published:
Updated: 2026-04-08T17:30:10.482Z
Reserved: 2024-10-04T12:11:50.517Z
Link: CVE-2024-9520
Updated: 2024-10-10T14:25:29.207Z
Status : Analyzed
Published: 2024-10-10T03:15:03.177
Modified: 2024-10-15T14:34:59.660
Link: CVE-2024-9520
No data.
OpenCVE Enrichment
No data.
EUVD