Media Manager for UserPro Missing Authorization Vulnerability in WordPress
Vulnerability
A vulnerability exists in the Media Manager for UserPro plugin for WordPress, affecting all versions through 3.12.0. The issue arises from a lack of proper capability checks in the upm_upload_media() function, allowing authenticated attackers with Subscriber-level access or higher to unauthorizedly modify data. This vulnerability can be exploited to change arbitrary options on the WordPress site, such as updating the default role for new users to administrator and enabling user registration, potentially granting administrative access to the attacker.
Impact
Exploitation of this vulnerability could lead to unauthorized privilege escalation, allowing attackers to gain administrative access on the affected WordPress site.
Vulnerability Rating
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.
