Blog | G5 Cyber Security

Convert Plus WordPress plugin flaw allows hackers to create Admin accounts

The WordPress plugin Convert Plus is affected by a critical flaw that could be exploited by an unauthenticated attacker to create accounts with administrator privileges. The vulnerability ties with the lack of filtering when processing a new user subscription via a form implemented by the plugin that already has more than 100,000 active installations. Experts at Defiant discovered that Convert Plus plugin includes an administrator role in a hidden field called cp_set_user Experts pointed out that the value for this field could be supplied by the same HTTP request as the rest of the subscription entry, and users can modify it.”]

Source: https://securityaffairs.co/wordpress/86292/breaking-news/convert-plus-wordpress-flaw.html

Exit mobile version