HomeDefault status
affected
Any version
affected
Description
The age-restriction WordPress plugin through 3.0.2 does not have authorisation in the age_restrictionRemoteSupportRequest function, allowing any authenticated users, such as subscriber to create an admin user with a hardcoded username and arbitrary password.
Problem types
CWE-269 Improper Privilege Management
Product status
Any version
Credits
Khaled Alenazi (Nxploited)
WPScan
References
wpscan.com/...rability/1a16440e-817f-4ec2-9c70-261f6b63fb8a/