Media Manager for UserPro Missing Authorization Vulnerability Allowing Privilege Escalation
Vulnerability
A vulnerability exists in the Media Manager for UserPro plugin for WordPress, all versions through 3.11.0, allowing unauthorized data modification that could lead to privilege escalation. The issue arises from a missing capability check in the add_capto_img() function, enabling unauthenticated attackers to update arbitrary options on the WordPress site. This vulnerability could be exploited to change the default registration role to administrator and activate user registration, granting administrative access to the attacker on the compromised site.
Impact
Exploitation of this vulnerability could result in unauthorized administrative access to a WordPress site.
Vulnerability Rating
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.
