Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-3858-cvv4-qvj7

Опубликовано: 15 дек. 2021
Источник: github
Github: Не прошло ревью

Описание

The RegistrationMagic WordPress plugin made it possible for unauthenticated users to log in as any site user, including administrators, if they knew a valid username on the site due to missing identity validation in the social login function social_login_using_email() of the plugin. This affects versions equal to, and less than, 5.0.1.7.

The RegistrationMagic WordPress plugin made it possible for unauthenticated users to log in as any site user, including administrators, if they knew a valid username on the site due to missing identity validation in the social login function social_login_using_email() of the plugin. This affects versions equal to, and less than, 5.0.1.7.

EPSS

Процентиль: 98%
0.57717
Средний

Дефекты

CWE-287

Связанные уязвимости

CVSS3: 9.8
nvd
около 4 лет назад

The RegistrationMagic WordPress plugin made it possible for unauthenticated users to log in as any site user, including administrators, if they knew a valid username on the site due to missing identity validation in the social login function social_login_using_email() of the plugin. This affects versions equal to, and less than, 5.0.1.7.

EPSS

Процентиль: 98%
0.57717
Средний

Дефекты

CWE-287