Security readout for executives and security teams
Plain-English summary
CVE-2024-52442 is a critical privilege escalation issue in the WordPress UserPlus plugin through version 2.0. The public record indicates an unauthenticated network attacker could gain elevated privileges, potentially affecting confidentiality, integrity, and availability. The bundle does not name a fixed version or confirmed exploitation.
Executive priority
Treat this as urgent for any WordPress estate using UserPlus. Affected sites may allow privilege escalation without authentication, creating a realistic path to site takeover. Immediate inventory and vendor-guidance review are warranted, especially for public-facing websites.
Technical view
The vulnerability is classified as CWE-266, Incorrect Privilege Assignment, in userplus/UserPlus through version 2.0. The CVSS 3.1 vector is AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H, scoring 9.8. No CPEs, exploit details, or patch version are provided in the source bundle.
Likely exposure
Exposure is most likely on WordPress sites where the UserPlus plugin is installed at version 2.0 or earlier. The affected metadata is limited, so teams should verify actual plugin presence and version from WordPress administration, filesystem inventory, or asset management records.
Exploitation context
The CVE is not listed as CISA KEV in the provided bundle, and no cited source confirms active exploitation. The CVSS vector indicates the issue is remotely reachable, low complexity, requires no privileges, and requires no user interaction, which makes exposed vulnerable installations urgent to assess.
Researcher notes
The available evidence supports critical severity and a high-impact privilege escalation class, but it does not provide exploit mechanics, proof of exploitation, or a fixed version. Validation should remain defensive: confirm deployment, version, administrative changes, and whether official remediation exists.
Mitigation direction
Inventory WordPress sites for the UserPlus plugin and installed version.
Check vendor and Patchstack guidance for a fixed release or official mitigation.
If no fix is available, disable or remove the plugin until guidance is available.
Review administrator accounts and recent privilege changes for unexpected activity.
Prioritize remediation on internet-facing WordPress sites.
Validation and detection
Confirm whether UserPlus is installed on each WordPress instance.
Record the installed plugin version and compare it with the affected range through 2.0.
Check logs for unexpected account creation, role changes, or administrator logins.
Verify whether a vendor-supported update or removal has been applied.
Document any uncertainty where plugin metadata or source evidence is incomplete.
Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.
Potential ATT&CK relevance
Conservative CVE-to-ATT&CK context
These mappings and lookup hints may be relevant to the vulnerability behavior, CWE, affected product, or exposure path. Glexia-inferred context is not an official MITRE, ATT&CK, CWE, or CVE Program mapping.
ATT&CK lookup starting points
Use these exact CWE pages and searches to review the Glexia ATT&CK library from this CVE's weakness and description context.
cwe · low confidence lookup
CWE-266: Exact CWE lookup
Use the exact CWE identifier as the starting point before reviewing related ATT&CK behavior. Open the exact CWE lookup page first, then review the ATT&CK searches from that MITRE weakness context. This is a Glexia lookup hint, not an official ATT&CK mapping.
The CVE wording references privilege impact, so privilege escalation and authorization behavior review may help. This is a Glexia inferred lookup path, not an official MITRE, ATT&CK, or CVE Program mapping.
These fields come from the CVE record and ADP containers, not from Glexia's Take. They preserve time-varying source decisions such as CISA SSVC, KEV status, CVSS metrics, and provider references.
1CVSS vectors
3Timeline events
1ADP providers
2Source links
SSVC decision data
CISA-ADPCISA Coordinator
Timestamp
Version
2.0.3
Exploitation: pocAutomatable: yesTechnical Impact: total
CVSS vector scores
1 official score
We collect every scored CVSS vector available in the official CNA and ADP containers. When more than one version is present, the table keeps the source vectors side by side instead of collapsing them into the highest score.
CWE links open Glexia weakness intelligence pages with official CWE context, developer remediation guidance, and related CVE mappings.
CWE-266 · source CWE mapping
Incorrect Privilege Assignment
Incorrect Privilege Assignment represents a recurring weakness pattern that can create exploitable paths when design, validation, or implementation controls are missing.