Vulnerability Description
WordPress Hybrid Composer 1.4.6 contains an unauthenticated settings change vulnerability that allows unauthenticated attackers to modify WordPress options by exploiting the hc_ajax_save_option action. Attackers can send POST requests to the admin-ajax.php endpoint with the action parameter set to hc_ajax_save_option to enable user registration and set the default role to administrator, enabling account takeover.
CVSS Score
CRITICAL
Related Weaknesses (CWE)
References
- http://wordpress.framework-y.com
- http://wordpress.framework-y.com/hybrid-composer/
- https://labs.sucuri.net/wptf-hybrid-composer-unauthenticated-arbitrary-options-u
- https://www.exploit-db.com/exploits/47154
- https://www.vulncheck.com/advisories/wordpress-hybrid-composer-unauthenticated-s
FAQ
What is CVE-2019-25738?
CVE-2019-25738 is a vulnerability with a CVSS score of 9.8 (CRITICAL). WordPress Hybrid Composer 1.4.6 contains an unauthenticated settings change vulnerability that allows unauthenticated attackers to modify WordPress options by exploiting the hc_ajax_save_option action...
How severe is CVE-2019-25738?
CVE-2019-25738 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2019-25738?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.