Description
The User Registration WordPress plugin before 2.12 does not prevent users with at least the contributor role from rendering sensitive shortcodes, allowing them to generate, and leak, valid password reset URLs, which they can use to take over any accounts.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
No advisories yet.
References
History
Fri, 09 May 2025 12:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Strategy11
Strategy11 user Registration Forms |
|
| Weaknesses | NVD-CWE-noinfo | |
| CPEs | cpe:2.3:a:strategy11:user_registration_forms:*:*:*:*:*:wordpress:*:* | |
| Vendors & Products |
Strategy11
Strategy11 user Registration Forms |
Fri, 01 Nov 2024 19:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: WPScan
Published:
Updated: 2024-11-01T18:30:42.850Z
Reserved: 2024-02-06T20:07:07.982Z
Link: CVE-2024-1290
Updated: 2024-08-01T18:33:25.378Z
Status : Analyzed
Published: 2024-03-11T18:15:18.003
Modified: 2025-05-09T12:18:34.000
Link: CVE-2024-1290
No data.
OpenCVE Enrichment
No data.
Weaknesses