Vulnerability record · CVE-2014-9013 · published 6 November 2019
CVE-2014-9013: WP Marketplace plugin ajaxinit allows arbitrary user creation and admin escalation
Wpmarketplace Project · Wpmarketplace
The ajaxinit function in wpmarketplace/libs/cart.php in WP Marketplace plugin 2.4.0 for WordPress fails to validate input, letting a remote authenticated user invoke wp_insert_user through wpmp_pp_ajax_call. An attacker with any low-privileged account can create arbitrary users, including administrators, and take over the site.
Description
The ajaxinit function in wpmarketplace/libs/cart.php in the WP Marketplace plugin 2.4.0 for WordPress allows remote authenticated users to create arbitrary users and gain admin privileges via a request to wpmp_pp_ajax_call with an execution target of wp_insert_user.
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Automated analysis
high priorityCVSS 8.8 and a very high EPSS percentile with public exploit code make this a serious escalation flaw, though it requires an authenticated account and no KEV listing is present.
What it is
The ajaxinit function in wpmarketplace/libs/cart.php in WP Marketplace plugin 2.4.0 for WordPress fails to validate input, letting a remote authenticated user invoke wp_insert_user through wpmp_pp_ajax_call. An attacker with any low-privileged account can create arbitrary users, including administrators, and take over the site.
Impact
An attacker gains full administrative control of the WordPress site, enabling content tampering, plugin and theme installation, and further compromise of the hosting environment.
Attack surface
Reachable over the network through the plugin's AJAX endpoint wpmp_pp_ajax_call; the attacker must be authenticated with at least a low-privileged account, and no user interaction is required.
Exploitation
No CISA KEV listing and no ransomware associations are recorded, but EPSS is 0.46939 (98.8th percentile) and a public Exploit-DB entry (36490) exists, indicating exploit code is available.
What to do
- Update or remove the WP Marketplace plugin; version 2.4.0 is the only version named in the record, so treat all older or unpatched copies as affected.
- If the plugin cannot be patched or removed, deactivate it until a fix is applied.
- Restrict and audit WordPress accounts, removing unused low-privileged users that could reach the AJAX endpoint.
- Add a web application firewall rule to block or rate-limit requests to wpmp_pp_ajax_call with an execution target of wp_insert_user.
- Review administrator accounts and roles for unauthorized additions.
Detection
- Monitor web server and WordPress logs for requests to wpmp_pp_ajax_call containing wp_insert_user.
- Alert on new user creation events, especially administrator accounts created outside normal administrative workflows.
- Audit WordPress user tables and role assignments for unexpected accounts.
- Correlate low-privileged account activity with subsequent user creation or privilege changes.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://www.exploit-db.com/exploits/36490/ | Third Party AdvisoryVDB Entry |
| https://www.exploit-db.com/exploits/36490/ | Third Party AdvisoryVDB Entry |
Track CVE-2014-9013 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2014-9013), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.