Описание
The RegistrationMagic WordPress plugin before 6.0.9.9 does not validate a client-supplied quantity multiplier when calculating the total price of a paid registration, allowing unauthenticated users to register without paying and obtain an activated account holding the role the form grants.
EPSS
Процентиль: 9%
0.00194
Низкий
5.3 Medium
CVSS3
Дефекты
CWE-472
Связанные уязвимости
CVSS3: 5.3
github
3 дня назад
The RegistrationMagic WordPress plugin before 6.0.9.9 does not validate a client-supplied quantity multiplier when calculating the total price of a paid registration, allowing unauthenticated users to register without paying and obtain an activated account holding the role the form grants.
EPSS
Процентиль: 9%
0.00194
Низкий
5.3 Medium
CVSS3
Дефекты
CWE-472