First published: Tue May 16 2023(Updated: )
The RegistrationMagic plugin for WordPress is vulnerable to Insecure Direct Object References in versions up to, and including, 5.2.0.5. This is due to the plugin providing user-controlled access to objects, letting a user bypass authorization and access system resources. This makes it possible for authenticated attackers, with administrator-level permissions and above, to change user passwords and potentially take over super-administrator accounts in multisite setup.
Credit: security@wordfence.com
Affected Software | Affected Version | How to fix |
---|---|---|
RegistrationMagic User Registration Plugin | <=5.2.0.5 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-2548 is a vulnerability in the RegistrationMagic plugin for WordPress that allows users to bypass authorization and access system resources.
CVE-2023-2548 is considered high severity with a CVSS score of 7.2.
The affected software for CVE-2023-2548 is the RegistrationMagic plugin for WordPress versions up to and including 5.2.0.5.
To fix CVE-2023-2548, update the RegistrationMagic plugin for WordPress to a version higher than 5.2.0.5.
More information about CVE-2023-2548 can be found on the Wordfence website and the CVE reference links provided.