CyberRota Analysis
AI-GeneratedThe CMP WordPress plugin prior to version 4.1.18 is vulnerable due to a lack of an option-name allow-list during AJAX settings imports, enabling users with Editor roles to modify arbitrary WordPress options. This flaw can lead to privilege escalation, potentially allowing Editors to gain Administrator access. WordPress site administrators using this plugin should prioritize updating to the latest version to mitigate this security risk.
Original NVD Description
The CMP WordPress plugin before 4.1.18 does not enforce an option-name allow-list when importing settings via one of its AJAX actions, allowing users with the Editor role (when the administrator has granted the Editor role access to the CMP WordPress plugin before 4.1.18's admin-bar controls) to update arbitrary WordPress options, including options that lead to privilege escalation to Administrator.