HyperComments <= 1.2.2 - Unauthenticated (Subscriber+) Arbitrary Options Update

CVE Details

Basic Information

Title HyperComments <= 1.2.2 - Unauthenticated (Subscriber+) Arbitrary Options Update
Type cve
Published 2025-06-05T11:15:05.674Z
Last Seen

Product Information

Vendor siteheart
Product HyperComments
Version *

CVSS Information

Base Score 9.8 (CRITICAL)
Attack Vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Confidentiality Impact
Integrity Impact
Availability Impact

AI Analysis

AI Description The HyperComments WordPress plugin has a vulnerability that allows unauthorized users to modify site settings, potentially leading to privilege escalation. This could enable attackers to create admin accounts, giving them full control over the site.
AI Severity Critical
Vendor siteheart
Product HyperComments
Affected Version 1.2.2

Affected Products

  • siteheart HyperComments *

Additional Information

CVE List
CWE List CWE-862
Bulletin Family

Description

The HyperComments plugin for WordPress is vulnerable to unauthorized modification of data that can lead to privilege escalation due to a missing capability check on the hc_request_handler function in all versions up to, and including, 1.2.2. This makes it possible for unauthenticated attackers to update arbitrary options on the WordPress site. This can be leveraged to update the default role for registration to administrator and enable user registration for attackers to gain administrative user access to a vulnerable site.

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.