CVE-2024-11350 – AdForest WordPress Privilege Escalation Vulnerability

CVE ID : CVE-2024-11350

Published : Jan. 8, 2025, 9:15 a.m. | 1 hour, 1 minute ago

Description : The AdForest theme for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 5.1.6. This is due to the plugin not properly validating a user’s identity prior to updating their password through the adforest_reset_password() function. This makes it possible for unauthenticated attackers to change arbitrary user’s passwords, including administrators, and leverage that to gain access to their account.

Severity: 9.8 | CRITICAL

Visit the link for more details, such as CVSS details, affected products, timeline, and more…

CVE-2024-11350 – AdForest WordPress Privilege Escalation Vulnerability