8.8
CVSSv3

CVE-2020-9454

CVSSv4: NA | CVSSv3: 8.8 | CVSSv2: 6.8 | VMScore: 980 | EPSS: 0.00422 | KEV: Not Included
Published: 06/03/2020 Updated: 21/11/2024

Vulnerability Summary

A CSRF vulnerability in the RegistrationMagic plugin up to and including 4.6.0.3 for WordPress allows remote malicious users to forge requests on behalf of a site administrator to change all settings for the plugin, including deleting users, creating new roles with escalated privileges, and allowing PHP file uploads via forms.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

metagauss registrationmagic