First published: Fri Mar 06 2020(Updated: )
In the RegistrationMagic plugin through 4.6.0.3 for WordPress, the export function allows remote authenticated users (with minimal privileges) to export submitted form data and settings via class_rm_form_controller.php rm_form_export.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Metagauss Registrationmagic | <=4.6.0.3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-9458 is a vulnerability in the RegistrationMagic plugin for WordPress, allowing remote authenticated users to export form data and settings.
The severity of CVE-2020-9458 is high with a CVSS score of 8.8.
CVE-2020-9458 allows remote authenticated users to export form data and settings in the RegistrationMagic plugin.
To fix CVE-2020-9458, ensure you have updated to RegistrationMagic plugin version 4.6.0.3 or higher.
You can find more information about CVE-2020-9458 in the references provided: https://wordpress.org/plugins/custom-registration-form-builder-with-submission-manager/#developers, https://wpvulndb.com/vulnerabilities/10116, https://www.wordfence.com/blog/2020/03/multiple-vulnerabilities-patched-in-registrationmagic-plugin/