Popis
The Invoice Generator plugin for WordPress is vulnerable to privilege escalation due to a missing capability check on the pravel_invoice_edit_account() AJAX action in versions up to, and including, 1.0.0. The handler is exposed via wp_ajax_nopriv_pravel_invoice_edit_account, accepts an attacker-controlled user_id and user_email from POST data, and calls wp_update_user() without verifying authentication, ownership, or a nonce. This makes it possible for unauthenticated attackers to change the email address of any user, including administrators, and then trigger WordPress-s password reset flow to gain access to the targeted account.
CVSS 9.8EPSS 0.662%Riziko 1.04
Zobraziť zdroj- Zverejnené
- 2026-06-27 05:16:41
- Dotknuté verzie
- <=1.0.0
- Typ
- Webová aplikácia
- Vektor
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H