CVE-2024-12822 is a critical privilege escalation vulnerability affecting all versions up to 3.11.0 of the Media Manager for UserPro plugin for WordPress. The flaw, a missing capability check in the add_capto_img() function, allows unauthenticated attackers to modify arbitrary WordPress options. This can be exploited to change the default user registration role to administrator, enabling attackers to gain full administrative access to the site. Rated 9.8 Critical on CVSS, this vulnerability is easily exploitable over the network with low attack complexity and no user interaction required, leading to complete compromise of confidentiality, integrity, and availability. While no public exploits or active exploitation have been observed, and community discussion is minimal, the high FAUCET Risk Score of 79/100 indicates significant potential impact.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 3.11.0CPE matchmatch criteria | cpe:2.3:a:userproplugin:media_manager:*:*:*:*:*:wordpress:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.