WordPress Admins Urged to Remove miniOrange Plugins Due to Critical Flaw
ID: 97943cf2-9238-5a3a-a213-c51d123a9cde
STIX ID: report--97943cf2-9238-5a3a-a213-c51d123a9cde
Feed Name: The Hacker News
WordPress plugins from miniOrange (Malware Scanner and Web Application Firewall) contain a critical unauthenticated privilege escalation (CVE-2024-2172, CVSS 9.8) due to a missing capability check allowing attackers to update user passwords and gain admin access; the plugins were permanently closed by maintainers and remain unpatched, exposing sites (Malware Scanner ~10,000 installs) to potential full compromise. The report also notes a separate high-severity, but patched, privilege escalation (CVE-2024-1991) in the RegistrationMagic plugin.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
