Export Function Vulnerability in RegistrationMagic Plugin for WordPress
CVE-2020-9458
8.8HIGH
Summary
The RegistrationMagic plugin for WordPress, specifically versions up to 4.6.0.3, contains an export function flaw located within the rm_form_export method of class_rm_form_controller.php. This vulnerability permits remote authenticated users, even those with minimal privileges, to access and export sensitive submitted form data and settings. This can lead to unintended data exposure, making it a critical concern for data security in applications using this plugin.
References
CVSS V3.1
Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved