CVE-2025-0177
CVE-2025-0177
Título es
CVE-2025-0177
Sáb, 08/03/2025 – 09:15
Tipo
CWE-269
Gravedad 2.0 Txt
Pendiente de análisis
Título en
CVE-2025-0177
Descripción en
The Javo Core plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including, 3.0.0.080. This is due to the plugin allowing users who are registering new accounts to set their own role. This makes it possible for unauthenticated attackers to gain elevated privileges by creating an account with the administrator role.
08/03/2025
08/03/2025
Vector CVSS:3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Gravedad 3.1 (CVSS 3.1 Base Score)
9.80
Gravedad 3.1 Txt Gravedad 3.1 (CVSS 3.1 Base Score)
CRITICAL
Referencias
https://themeforest.net/item/javo-directory-wordpress-theme/8390513#item-description__update-history
https://www.wordfence.com/threat-intel/vulnerabilities/id/7d636768-37b4-4343-9028-30e7b1f997f2?source=cve
Enviar en el boletín
Off
