← back
CVE-2024-50483criticalCWE-639

WordPress Meetup plugin <= 0.1 - Broken Authentication vulnerability

48Vexday Risk Score

No sign of exploitation. It has a public proof of concept.

ssvc Attendcvss 9.8epss 2.4%
from disclosure to weapon8 days
Published on NVDOct 28
1st PoC+8d
exploitation probability
2.4%top 18% of all CVEs
observed exploitation
nono source reports it
1 public exploit(s)
In short

The WordPress Meetup plugin version 0.1 and earlier allows attackers to bypass authentication checks by manipulating user-controlled keys, enabling them to gain unauthorized administrative privileges without valid credentials.

Technical detail

The plugin fails to properly validate authentication keys, permitting an unauthenticated attacker to escalate privileges through CWE-639 (Authorization Bypass via User-Controlled Key). An attacker can forge or manipulate authentication parameters to assume higher privilege levels without requiring legitimate credentials or prior access.

Summary generated and translated by AI from the official description.
Authorization Bypass Through User-Controlled Key vulnerability in Tareq Hasan Meetup meetup allows Privilege Escalation.This issue affects Meetup: from n/a through <= 0.1.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Affected products
Tareq Hasan · Meetup
⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.