๐Ÿ” CVE Alert

CVE-2024-9215

HIGH 8.8

Co-Authors, Multiple Authors and Guest Authors in an Author Box with PublishPress Authors <= 4.7.1 - Insecure Direct Object Reference to Authenticated (Author+) Arbitrary User Email Update and Account Takeover

CVSS Score
8.8
EPSS Score
0.0%
EPSS Percentile
0th

The Co-Authors, Multiple Authors and Guest Authors in an Author Box with PublishPress Authors plugin for WordPress is vulnerable to Insecure Direct Object Reference to Privilege Escalation/Account Takeover in all versions up to, and including, 4.7.1 via the action_edited_author() due to missing validation on the 'authors-user_id' user controlled key. This makes it possible for authenticated attackers, with Author-level access and above, to update arbitrary user accounts email addresses, including administrators, which can then be leveraged to reset that user's account password and gain access.

CWE CWE-639
Vendor publishpress
Product co-authors, multiple authors and guest authors in an author box with publishpress authors
Published Oct 17, 2024
Last Updated Apr 8, 2026
Stay Ahead of the Next One

Get instant alerts for publishpress co-authors, multiple authors and guest authors in an author box with publishpress authors

Be the first to know when new high vulnerabilities affecting publishpress co-authors, multiple authors and guest authors in an author box with publishpress authors are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability

Affected Versions

publishpress / Co-Authors, Multiple Authors and Guest Authors in an Author Box with PublishPress Authors
0 โ‰ค 4.7.1

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
wordfence.com: https://www.wordfence.com/threat-intel/vulnerabilities/id/d0506137-82e3-4988-9b23-370465a866c0?source=cve plugins.trac.wordpress.org: https://plugins.trac.wordpress.org/browser/publishpress-authors/tags/4.7.1/src/core/Classes/Author_Editor.php#L594 plugins.trac.wordpress.org: https://plugins.trac.wordpress.org/changeset?sfp_email=&sfph_mail=&reponame=&old=3169244%40publishpress-authors&new=3169244%40publishpress-authors&sfp_email=&sfph_mail=#file7

Credits

wesley