Authentication Bypass Vulnerability Affects User Registration Forms
CVE-2024-11293
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 4 December 2024
What is CVE-2024-11293?
The Registration Forms – User Registration Forms, Invitation-Based Registrations, Front-end User Profile, Login Form & Content Restriction Social Sites Login plugin for WordPress suffers from a vulnerability that allows unauthenticated attackers to bypass authentication mechanisms. This issue arises from inadequate validation of users being authenticated through social login tokens. If an attacker knows an existing user's email address and the user does not have an account with the service that returns the social login token, they can gain unauthorized access, potentially compromising any user account on the site, including administrative accounts. It's crucial for users of this plugin to update to a secure version to mitigate this threat.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
Pie Register - Social Sites Login (Add on) * <= 1.7.9
References
CVSS V3.1
Timeline
Vulnerability published