logo

WordPress Admins Urged to Remove miniOrange Plugins Due to Critical Flaw

ID: 97943cf2-9238-5a3a-a213-c51d123a9cde

STIX ID: report--97943cf2-9238-5a3a-a213-c51d123a9cde

Feed Name: The Hacker News

Threat Score
85/100

Date Published: 2024-03-18

Date Updated: 2026-04-24

Author: [email protected] (The Hacker News)

...
...

WordPress plugins from miniOrange (Malware Scanner and Web Application Firewall) contain a critical unauthenticated privilege escalation (CVE-2024-2172, CVSS 9.8) due to a missing capability check allowing attackers to update user passwords and gain admin access; the plugins were permanently closed by maintainers and remain unpatched, exposing sites (Malware Scanner ~10,000 installs) to potential full compromise. The report also notes a separate high-severity, but patched, privilege escalation (CVE-2024-1991) in the RegistrationMagic plugin.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.