The Wux Blog Editor plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 3.0.0. This is due to missing validation on the token being supplied during the autologin through the plugin. This makes it possible for unauthenticated attackers to log in to the first administrator user.
Metrics
Affected Vendors & Products
References
History
Mon, 28 Oct 2024 20:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Jurre De Klijn
Jurre De Klijn wux Blog Editor |
|
CPEs | cpe:2.3:a:jurre_de_klijn:wux_blog_editor:*:*:*:*:*:*:*:* | |
Vendors & Products |
Jurre De Klijn
Jurre De Klijn wux Blog Editor |
|
Metrics |
ssvc
|
Sat, 26 Oct 2024 02:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | The Wux Blog Editor plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 3.0.0. This is due to missing validation on the token being supplied during the autologin through the plugin. This makes it possible for unauthenticated attackers to log in to the first administrator user. | |
Title | Wux Blog Editor <= 3.0.0 - Authentication Bypass to Administrator | |
Weaknesses | CWE-288 | |
References |
| |
Metrics |
cvssV3_1
|

Status: PUBLISHED
Assigner: Wordfence
Published:
Updated: 2024-10-28T19:40:11.760Z
Reserved: 2024-10-14T11:53:29.303Z
Link: CVE-2024-9931

Updated: 2024-10-28T19:39:45.592Z

Status : Awaiting Analysis
Published: 2024-10-26T03:15:04.770
Modified: 2024-10-28T13:58:09.230
Link: CVE-2024-9931

No data.