Unauthenticated Attackers Can Escalate Privileges via Plugin Flaw
CVE-2024-10508
Key Information:
- Vendor
Wordpress
- Vendor
- CVE Published:
- 9 November 2024
What is CVE-2024-10508?
The RegistrationMagic User Registration Plugin for WordPress is susceptible to a serious vulnerability that allows unauthenticated attackers to escalate privileges via account takeover. This issue stems from the plugin's inadequate validation of password reset tokens prior to allowing updates to user passwords. As a result, attackers can reset passwords for arbitrary users, including those with administrative privileges, and gain unauthorized access to sensitive accounts. The vulnerability exists in all versions up to and including 6.0.2.6, necessitating immediate attention and patching to mitigate risks associated with potential exploitation.
Affected Version(s)
RegistrationMagic – User Registration Plugin with Custom Registration Forms * <= 6.0.2.6
References
EPSS Score
5% chance of being exploited in the next 30 days.
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved