The Profitori plugin for WordPress is vulnerable to...
Critical severity
Unreviewed
Published
May 31, 2025
to the GitHub Advisory Database
•
Updated May 31, 2025
Description
Published by the National Vulnerability Database
May 31, 2025
Published to the GitHub Advisory Database
May 31, 2025
Last updated
May 31, 2025
The Profitori plugin for WordPress is vulnerable to Privilege Escalation due to a missing capability check on the stocktend_object endpoint in versions 2.0.6.0 to 2.1.1.3. This makes it possible to trigger the save_object_as_user() function for objects whose '_datatype' is set to 'users',. This allows unauthenticated attackers to write arbitrary strings straight into the user’s wp_capabilities meta field, potentially elevating the privileges of an existing user account or a newly created one to that of an administrator.
References