The admin-management-xtended plugin before 2.4.0.1 for WordPress has privilege escalation because wp_ajax functions are mishandled.
References
Link | Resource |
---|---|
https://security.szurek.pl/admin-management-xtended-240-privilege-escalation.html | Exploit Third Party Advisory |
https://wordpress.org/plugins/admin-management-xtended/#developers | Release Notes Third Party Advisory |
https://security.szurek.pl/admin-management-xtended-240-privilege-escalation.html | Exploit Third Party Advisory |
https://wordpress.org/plugins/admin-management-xtended/#developers | Release Notes Third Party Advisory |
Configurations
Configuration 1 (hide)
|
History
21 Nov 2024, 02:40
Type | Values Removed | Values Added |
---|---|---|
References | () https://security.szurek.pl/admin-management-xtended-240-privilege-escalation.html - Exploit, Third Party Advisory | |
References | () https://wordpress.org/plugins/admin-management-xtended/#developers - Release Notes, Third Party Advisory |
Information
Published : 2019-09-20 15:15
Updated : 2024-11-21 02:40
NVD link : CVE-2015-9390
Mitre link : CVE-2015-9390
CVE.ORG link : CVE-2015-9390
JSON object : View
Products Affected
admin_management_xtended_project
- admin_management_xtended
CWE
CWE-269
Improper Privilege Management