The User Registration WordPress plugin before 2.12 does not prevent users with at least the contributor role from rendering sensitive shortcodes, allowing them to generate, and leak, valid password reset URLs, which they can use to take over any accounts.
References
| Link | Resource |
|---|---|
| https://wpscan.com/vulnerability/a60187d4-9491-435a-bc36-8dd348a1ffa3/ | Exploit Third Party Advisory |
| https://wpscan.com/vulnerability/a60187d4-9491-435a-bc36-8dd348a1ffa3/ | Exploit Third Party Advisory |
Configurations
History
No history.
Information
Published : 2024-03-11 18:15
Updated : 2025-05-09 12:18
NVD link : CVE-2024-1290
Mitre link : CVE-2024-1290
CVE.ORG link : CVE-2024-1290
JSON object : View
Products Affected
strategy11
- user_registration_forms
CWE
