CVE-2024-8485 is a critical privilege escalation vulnerability affecting the REST API TO MiniProgram plugin for WordPress, impacting all versions up to and including 4.7.1. The flaw lies in the updateUserInfo() function, which lacks proper validation for the 'openid' parameter, allowing unauthenticated attackers to modify arbitrary user accounts. This enables attackers to change user emails to a @weixin.com address, subsequently facilitating password resets for any account, including administrators. With a CVSS score of 9.8 (CRITICAL), this vulnerability is easily exploitable over the network with low complexity and no user interaction, leading to complete compromise of confidentiality, integrity, and availability. While there is no evidence of active exploitation in the wild (not in KEV), exploit code is not publicly available on common platforms like Metasploit, Nuclei, or ExploitDB. However, the vulnerability is garnering significant community discussion, with 10 mentions, indicating active interest and potential for future exploitation.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 4.7.1CPE matchmatch criteria | cpe:2.3:a:jianbo:rest_api_to_miniprogram:*:*:*:*:*:wordpress:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.