The User Registration WordPress plugin before 2.12 does not prevent users with at least the contributor role from rendering sensitive shortcodes, allowing them to generate, and leak, valid password reset URLs, which they can use to take over any accounts.
References
Link | Resource |
---|---|
https://wpscan.com/vulnerability/a60187d4-9491-435a-bc36-8dd348a1ffa3/ | Exploit Third Party Advisory |
https://wpscan.com/vulnerability/a60187d4-9491-435a-bc36-8dd348a1ffa3/ | Exploit Third Party Advisory |
Configurations
History
09 May 2025, 12:18
Type | Values Removed | Values Added |
---|---|---|
CWE | NVD-CWE-noinfo | |
First Time |
Strategy11
Strategy11 user Registration Forms |
|
CPE | cpe:2.3:a:strategy11:user_registration_forms:*:*:*:*:*:wordpress:*:* | |
References | () https://wpscan.com/vulnerability/a60187d4-9491-435a-bc36-8dd348a1ffa3/ - Exploit, Third Party Advisory |
21 Nov 2024, 08:50
Type | Values Removed | Values Added |
---|---|---|
References | () https://wpscan.com/vulnerability/a60187d4-9491-435a-bc36-8dd348a1ffa3/ - |
01 Nov 2024, 19:35
Type | Values Removed | Values Added |
---|---|---|
CVSS |
v2 : v3 : |
v2 : unknown
v3 : 6.5 |
Summary |
|
11 Mar 2024, 18:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2024-03-11 18:15
Updated : 2025-05-09 12:18
NVD link : CVE-2024-1290
Mitre link : CVE-2024-1290
CVE.ORG link : CVE-2024-1290
JSON object : View
Products Affected
strategy11
- user_registration_forms
CWE