HIGH

CVE-2014-9013

CVSS v3

8.8

HIGH

EPSS Score

17.7%

exploit probability

CISA KEV

No

known exploited

Exploitation

SSVC status

Description

The ajaxinit function in wpmarketplace/libs/cart.php in the WP Marketplace plugin 2.4.0 for WordPress allows remote authenticated users to create arbitrary users and gain admin privileges via a request to wpmp_pp_ajax_call with an execution target of wp_insert_user.

Technical details

Published
11/6/2019

Frequently asked questions

What is CVE-2014-9013?

The ajaxinit function in wpmarketplace/libs/cart.php in the WP Marketplace plugin 2.4.0 for WordPress allows remote authenticated users to create arbitrary users and gain admin privileges via a request to wpmp_pp_ajax_call with an execution target of wp_insert_user.

Is CVE-2014-9013 actively exploited?

Active exploitation of CVE-2014-9013 has not been confirmed. The EPSS score is 17.7%, indicating the estimated probability of exploitation in the next 30 days.

What is the CVSS score for CVE-2014-9013?

CVE-2014-9013 has a CVSS v3 base score of 8.8 (HIGH severity).

Is CVE-2014-9013 affecting your environment?

Use isMalicious to check if any of your IPs or domains are associated with this vulnerability's IOCs.

Other 2014 vulnerabilities worth triaging

Ranked by exploit probability (EPSS).