CVE-2024-1290
Formidable Registration < 2.12 - Contributor+ Arbitrary User Password Reset To Account Takeover
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
1Exploited in Wild
-Decision
Descriptions
The User Registration WordPress plugin before 2.12 does not prevent users with at least the contributor role from rendering sensitive shortcodes, allowing them to generate, and leak, valid password reset URLs, which they can use to take over any accounts.
El complemento User Registration de WordPress anterior a 2.12 no impide que los usuarios con al menos el rol de colaborador muestren códigos cortos confidenciales, lo que les permite generar y filtrar URL válidas para restablecer contraseñas, que pueden usar para hacerse cargo de cualquier cuenta.
The WordPress User Registration Forms by Formidable Forms plugin for WordPress is vulnerable to arbitrary user password reset and account takeover in all versions up to, and including, 2.11. This is due to the plugin allowing users with access to the editor to utilize the frm-set-password-link shortcode and supply any user ID. This makes it possible for authenticated attackers, with contributor-level access and above, to reset the password of any user account and achieve account takeover
CVSS Scores
SSVC
- Decision:Track
Timeline
- 2024-02-06 CVE Reserved
- 2024-02-19 CVE Published
- 2024-03-12 EPSS Updated
- 2024-11-01 CVE Updated
- 2024-11-01 First Exploit
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
- CWE-862: Missing Authorization
CAPEC
References (1)
URL | Tag | Source |
---|
URL | Date | SRC |
---|---|---|
https://wpscan.com/vulnerability/a60187d4-9491-435a-bc36-8dd348a1ffa3 | 2024-11-01 |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Unknown Search vendor "Unknown" | User Registration Search vendor "Unknown" for product "User Registration" | < 2.12 Search vendor "Unknown" for product "User Registration" and version " < 2.12" | en |
Affected
|