Description

The DHVC Form plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including, 2.4.7. This is due to the plugin allowing a user to supply the 'role' field when registering. This makes it possible for unauthenticated attackers to register as an administrator on sites.

INFO

Published Date :

2025-02-28T08:23:19.298Z

Last Modified :

2025-02-28T14:45:44.819Z

Source :

Wordfence
AFFECTED PRODUCTS

The following products are affected by CVE-2024-8420 vulnerability.

Vendors Products
Sitesao
  • Dhvc Form
REFERENCES

CVSS Vulnerability Scoring System

Detailed values of each vector for above chart.
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality Impact
Integrity Impact
Availability Impact