The Malware Scanner plugin and the Web Application Firewall plugin for WordPress (both by MiniOrange) are vulnerable to privilege escalation due to a missing capability check on the mo_wpns_init() function in all versions up to, and including, 4.7.2 (for Malware Scanner) and 2.1.1 (for Web Application Firewall). This makes it possible for unauthenticated attackers to escalate their privileges to that of an administrator.
Metrics
Affected Vendors & Products
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-27135 | The Malware Scanner plugin and the Web Application Firewall plugin for WordPress (both by MiniOrange) are vulnerable to privilege escalation due to a missing capability check on the mo_wpns_init() function in all versions up to, and including, 4.7.2 (for Malware Scanner) and 2.1.1 (for Web Application Firewall). This makes it possible for unauthenticated attackers to escalate their privileges to that of an administrator. |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Thu, 26 Feb 2026 11:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Miniorange
Miniorange malware Scanner Miniorange web Application Firewall |
|
| CPEs | cpe:2.3:a:miniorange:malware_scanner:*:*:*:*:*:wordpress:*:* cpe:2.3:a:miniorange:web_application_firewall:*:*:*:*:*:*:*:* |
|
| Vendors & Products |
Miniorange
Miniorange malware Scanner Miniorange web Application Firewall |
|
| Metrics |
ssvc
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: Wordfence
Published:
Updated: 2024-08-01T19:03:39.304Z
Reserved: 2024-03-04T18:27:27.719Z
Link: CVE-2024-2172
Updated: 2024-08-01T19:03:39.304Z
Status : Awaiting Analysis
Published: 2024-03-13T16:15:32.043
Modified: 2024-11-21T09:09:10.853
Link: CVE-2024-2172
No data.
OpenCVE Enrichment
No data.
Weaknesses
No weakness.
EUVD