First published: Fri Mar 06 2020(Updated: )
In the RegistrationMagic plugin through 4.6.0.3 for WordPress, the user controller allows remote authenticated users (with minimal privileges) to elevate their privileges to administrator via class_rm_user_controller.php rm_user_edit.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
RegistrationMagic User Registration Plugin | <=4.6.0.3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-9456 is a vulnerability in the RegistrationMagic plugin through 4.6.0.3 for WordPress that allows remote authenticated users to elevate their privileges to administrator.
CVE-2020-9456 has a severity score of 8.8, which is considered high.
CVE-2020-9456 affects the RegistrationMagic plugin through version 4.6.0.3 for WordPress.
To fix CVE-2020-9456, you should update the RegistrationMagic plugin to a version beyond 4.6.0.3.
You can find more information about CVE-2020-9456 at the following references: [1] [2] [3].