Home

Description

The Profitori plugin for WordPress is vulnerable to Privilege Escalation due to a missing capability check on the stocktend_object endpoint in versions 2.0.6.0 to 2.1.1.3. This makes it possible to trigger the save_object_as_user() function for objects whose '_datatype' is set to 'users',. This allows unauthenticated attackers to write arbitrary strings straight into the user’s wp_capabilities meta field, potentially elevating the privileges of an existing user account or a newly created one to that of an administrator.

PUBLISHED Reserved 2025-05-12 | Published 2025-05-31 | Updated 2025-06-02 | Assigner Wordfence




CRITICAL: 9.8CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Problem types

CWE-285 Improper Authorization

Product status

Default status
unaffected

2.0.6.0 (semver)
affected

Timeline

2025-05-30:Disclosed

Credits

Kenneth Dunn finder

References

www.wordfence.com/...-e9dc-4c3d-b696-5792e70ff0b6?source=cve

plugins.trac.wordpress.org/...ori/tags/2.1.1.3/profitori.php

plugins.trac.wordpress.org/...ori/tags/2.1.1.3/profitori.php

plugins.trac.wordpress.org/...ori/tags/2.1.1.3/profitori.php

wordpress.org/plugins/profitori/

plugins.trac.wordpress.org/...ori/tags/2.1.1.3/profitori.php

cve.org (CVE-2025-4631)

nvd.nist.gov (CVE-2025-4631)

Download JSON