PoC Index

CVE-2023-3460

CRITICAL 9.8EPSS 72.3%

The Ultimate Member WordPress plugin before 2.6.7 does not prevent visitors from creating user accounts with arbitrary capabilities, effectively allowing attackers to create administrator accounts at will. This is actively being exploited in the wild.

CVSS v3.1
9.8 CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS
72.31% chance of exploitation in the next 30 days, 99th percentile
Nuclei
critical · CWE-269
Published
2023-07-04
Updated
2024-11-25

Proof-of-concept exploits (12)

Nuclei templates (1)

ExploitDB entries (1)

References

Related