Authentication Bypass Vulnerability Affects User Registration Forms
CVE-2024-11293

8.1HIGH

Key Information:

Vendor

WordPress

Vendor
CVE Published:
4 December 2024

What is CVE-2024-11293?

The Registration Forms – User Registration Forms, Invitation-Based Registrations, Front-end User Profile, Login Form & Content Restriction Social Sites Login plugin for WordPress suffers from a vulnerability that allows unauthenticated attackers to bypass authentication mechanisms. This issue arises from inadequate validation of users being authenticated through social login tokens. If an attacker knows an existing user's email address and the user does not have an account with the service that returns the social login token, they can gain unauthorized access, potentially compromising any user account on the site, including administrative accounts. It's crucial for users of this plugin to update to a secure version to mitigate this threat.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.

Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.

Affected Version(s)

Pie Register - Social Sites Login (Add on) * <= 1.7.9

References

CVSS V3.1

Score:
8.1
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

.