← Back to CVE List

CVE-2024-8420

Published: 2025-02-28T09:15Z
Last Modified: 2025-03-06T16:36Z
Source: MITRE CVE List
License: MITRE-CVE-TOS
The DHVC Form plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including, 2.4.7. This is due to the plugin allowing a user to supply the 'role' field when registering. This makes it possible for unauthenticated attackers to register as an administrator on sites. > MITRE Terms of Use apply – see LICENSE‑MITRE.txt