CVE-2020-9456: High severity Metagauss Registrationmagic Wordpress vulnerability
In the RegistrationMagic plugin through 4.6.0.3 for WordPress, the user controller allows remote authenticated users (with minimal privileges) to elevate their privileges to administrator via classrmusercontroller.php rmuseredit.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2020-9456?
CVE-2020-9456 is a vulnerability in the RegistrationMagic plugin through 4.6.0.3 for WordPress that allows remote authenticated users to elevate their privileges to administrator.
How severe is CVE-2020-9456?
CVE-2020-9456 has a severity score of 8.8, which is considered high.
How does CVE-2020-9456 affect the RegistrationMagic plugin?
CVE-2020-9456 affects the RegistrationMagic plugin through version 4.6.0.3 for WordPress.
How can I fix CVE-2020-9456?
To fix CVE-2020-9456, you should update the RegistrationMagic plugin to a version beyond 4.6.0.3.
Where can I find more information about CVE-2020-9456?
You can find more information about CVE-2020-9456 at the following references: [1] [2] [3].