The admin-management-xtended plugin before 2.4.0.1 for WordPress has privilege escalation because wp_ajax functions are mishandled.
The product does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control for that actor.
Link | Tags |
---|---|
https://wordpress.org/plugins/admin-management-xtended/#developers | third party advisory release notes |
https://security.szurek.pl/admin-management-xtended-240-privilege-escalation.html | third party advisory exploit |