7.2
CVSSv3

CVE-2023-2548

CVSSv4: NA | CVSSv3: 7.2 | CVSSv2: NA | VMScore: 820 | EPSS: 0.00033 | KEV: Not Included
Published: 16/05/2023 Updated: 21/11/2024

Vulnerability Summary

The RegistrationMagic plugin for WordPress is vulnerable to Insecure Direct Object References in versions up to, and including, 5.2.0.5. This is due to the plugin providing user-controlled access to objects, letting a user bypass authorization and access system resources. This makes it possible for authenticated attackers, with administrator-level permissions and above, to change user passwords and potentially take over super-administrator accounts in multisite setup.

Vulnerable Product Search on Vulmon Subscribe to Product

metagauss registrationmagic – custom registration forms, user registration, payment, and user login

metagauss registrationmagic