Croma Music WordPress Plugin Privilege Escalation Vulnerability

Vulnerability

A vulnerability in the Croma Music plugin for WordPress, present in versions through 3.6, allows authenticated users with Subscriber-level access and above to arbitrarily modify options on the WordPress site. This issue arises from a missing capability check in the 'ironMusic_ajax' function, which can be exploited to escalate privileges by changing the default role for new users to administrator and enabling user registration, potentially leading to unauthorized administrative access.

Impact

Exploitation of this vulnerability could result in unauthorized administrative access to a WordPress site by allowing attackers to change user roles and permissions.

Remediation

Users are advised to update the Croma Music plugin to version 3.6.1 or later.

Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
5.0
exploitability
5.2
remediation
7.7
relevance
0.0
threat
0.0
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.