12 results (0.001 seconds)

CVSS: 6.1EPSS: 0%CPEs: 1EXPL: 1

The Registration Forms WordPress plugin before 3.8.2.3 does not properly validate the redirection URL when logging in and login out, leading to an Open Redirect vulnerability The Pie Register plugin for WordPress is vulnerable to Open Redirect via the 'redirect_to' parameter in versions up to, and including, 3.8.2.2 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to redirect users to an external site, if they can successfully trick a user into performing an action such as clicking on a link. • https://wpscan.com/vulnerability/832c6155-a413-4641-849c-b98ba55e8551 • CWE-601: URL Redirection to Untrusted Site ('Open Redirect') •

CVSS: 6.5EPSS: 0%CPEs: 1EXPL: 1

The Registration Forms WordPress plugin before 3.8.1.3 does not have authorisation and CSRF when deleting users via an init action handler, allowing unauthenticated attackers to delete arbitrary users (along with their posts) El complemento de WordPress Registration Forms anterior a 3.8.1.3 no tiene autorización ni CSRF al eliminar usuarios a través de un controlador de acción init, lo que permite a atacantes no autenticados eliminar usuarios arbitrarios (junto con sus publicaciones). The Pie Register plugin for WordPress is vulnerable to arbitrary user deletion in versions up to, and including, 3.8.1.3. This is due to missing validation and capability checking on code that handles the deletion of users. This makes it possible for unauthenticated attackers to delete arbitrary users. • https://wpscan.com/vulnerability/a087fb45-6f6c-40ac-b48b-2cbceda86cbe • CWE-352: Cross-Site Request Forgery (CSRF) CWE-862: Missing Authorization •

CVSS: 9.8EPSS: 20%CPEs: 1EXPL: 1

The Registration Forms – User profile, Content Restriction, Spam Protection, Payment Gateways, Invitation Codes WordPress plugin before 3.7.1.6 does not properly escape user data before using it in a SQL statement in the wp-json/pie/v1/login REST API endpoint, leading to an SQL injection. El plugin Registration Forms - User profile, Content Restriction, Spam Protection, Payment Gateways, Invitation Codes de WordPress versiones anteriores a 3.7.1.6, no escapa correctamente los datos del usuario antes de usarlos en una sentencia SQL en el endpoint wp-json/pie/v1/login REST API, conllevando a una inyección SQL • https://wpscan.com/vulnerability/6bed00e4-b363-43b8-a392-d068d342151a • CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') •

CVSS: 8.1EPSS: 16%CPEs: 1EXPL: 2

The Registration Forms – User profile, Content Restriction, Spam Protection, Payment Gateways, Invitation Codes WordPress plugin before 3.1.7.6 has a flaw in the social login implementation, allowing unauthenticated attacker to login as any user on the site by only knowing their user ID or username El plugin Registration Forms - User profile, Content Restriction, Spam Protection, Payment Gateways, Invitation Codes de WordPress versiones anteriores a 3.1.7.6, presenta un fallo en la implementación del login social, permitiendo a un atacante no autenticado iniciar sesión como cualquier usuario del sitio con sólo conocer su ID de usuario o nombre de usuario The Registration Forms User profile, Content Restriction, Spam Protection, Payment Gateways, Invitation Codes WordPress plugin before 3.1.7.6 has a flaw in the social login implementation, allowing unauthenticated attacker to login as any user on the site by only knowing their user ID or username • https://github.com/RandomRobbieBF/CVE-2021-24647 https://wpscan.com/vulnerability/40d347b1-b86e-477d-b4c6-da105935ce37 • CWE-287: Improper Authentication •

CVSS: 6.1EPSS: 0%CPEs: 1EXPL: 1

The Pie Register – User Registration Forms. Invitation based registrations, Custom Login, Payments WordPress plugin before 3.7.0.1 does not sanitise the invitaion_code GET parameter when outputting it in the Activation Code page, leading to a reflected Cross-Site Scripting issue. Los Formularios Pie Register - User Registration. El plugin Invitation based registrations, Custom Login, Payments WordPress versiones anteriores a 3.7.0.1 no sanean el parámetro GET invitaion_code al generarlo en la página del código de activación, conllevando un problema de tipo Cross-Site Scripting • https://plugins.trac.wordpress.org/changeset/2507536 https://wpscan.com/vulnerability/f1b67f40-642f-451e-a67a-b7487918ee34 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •