PT-2024-16328 · WordPress · Registrationmagic

Khayal Farzaliyev

+1

·

Published

2024-11-09

·

Updated

2024-11-14

·

CVE-2024-10508

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions RegistrationMagic – User Registration Plugin with Custom Registration Forms plugin for WordPress versions up to, and including, 6.0.2.6
Description The issue is due to the plugin not properly validating the password reset token prior to updating a user's password. This makes it possible for unauthenticated attackers to reset the password of arbitrary users, including administrators, and gain access to these accounts. The vulnerability allows for privilege escalation via account takeover.
Recommendations Update to the latest version to secure your site. As a temporary workaround, consider restricting access to the password reset functionality until a patch is available. Avoid using the vulnerable password reset token until the issue is resolved.

Fix

Weakness Enumeration

Related Identifiers

CVE-2024-10508

Affected Products

Registrationmagic