MultiManager WP – Manage All Your WordPress Sites Easily: Privilege escalation or authentication bypass
MultiManager WP – Manage All Your WordPress Sites Easily is affected by privilege escalation or authentication bypass. The vulnerable path is reachable without authentication. A successful request can grant permissions or access that the caller should not possess.
- Component
- MultiManager WP – Manage All Your WordPress Sites Easily
- Plugin slug
multimanager-wp- Affected
- See vendor advisory
- Safe version
- See mitigation notes
- Published
- Nov 13, 2024
This CVE was published Nov 13, 2024 and is one of 1 known issue for this plugin.
Update, patch or deactivate.
Update MultiManager WP – Manage All Your WordPress Sites Easily to a release outside the affected range, or disable and remove it until a fixed version is available.
No confirmed safe version is listed. Consider a vendor-supported patch or temporarily restricting the affected functionality while you assess the risk.
Deactivate only when warranted by your risk profile, or when advised by your hosting provider in the limited circumstances where the vulnerability cannot otherwise be mitigated. If you’re unsure which action is appropriate, contact Fused or your hosting provider for guidance.
Technical description
The MultiManager WP – Manage All Your WordPress Sites Easily plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and including, 1.0.5. This is due to the user impersonation feature inappropriately determining the current user via user-supplied input. This makes it possible for unauthenticated attackers to generate an impersonation link that will allow them to log in as any existing user, such as an administrator. NOTE: The user impersonation feature was disabled in version 1.1.0 and re-enabled with a patch in version 1.1.2.
CVE / CNA vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H