CVE-2024-6069
EUVD-2024-4722709.07.2024, 09:15
The Registration Forms – User Registration Forms, Invitation-Based Registrations, Front-end User Profile, Login Form & Content Restriction plugin for WordPress is vulnerable to unauthorized arbitrary plugin installation due to a missing capability check on the pieregister_install_addon function in all versions up to, and including, 3.8.3.4. This makes it possible for authenticated attackers, with subscriber-level access and above, to install arbitrary plugins. As a result attackers might achieve code execution on the targeted serverEnginsight
Early Detection
Affected products identified ahead of NVD analysis through intelligence sources.
| Vendor | Product | Version | Source |
|---|---|---|---|
| genetech_products | registration_forms | 𝑥 ≤ 3.8.3.4 | ADP |
| genetech_products | user_registration_forms | 𝑥 ≤ 3.8.3.4 | ADP |
| genetech_products | front_end_user_profile_login_form | 𝑥 ≤ 3.8.3.4 | ADP |
| genetech_products | invitation_based_registrations | 𝑥 ≤ 3.8.3.4 | ADP |
| genetech_products | content_registration | 𝑥 ≤ 3.8.3.4 | ADP |
Common Weakness Enumeration
References