First published: Mon Mar 13 2023(Updated: )
Cross-Site Request Forgery (CSRF) vulnerability in RegistrationMagic plugin <= 5.1.9.2 versions.
Credit: audit@patchstack.com
Affected Software | Affected Version | How to fix |
---|---|---|
Metagauss Registrationmagic | <5.1.9.3 |
Update to 5.1.9.3 or a higher version.
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-25991 is a Cross-Site Request Forgery (CSRF) vulnerability found in the RegistrationMagic plugin versions <= 5.1.9.2.
The severity of CVE-2023-25991 is high, with a CVSS score of 8.8.
The RegistrationMagic plugin versions up to and exclusive of 5.1.9.3 are affected by CVE-2023-25991.
To fix CVE-2023-25991, update the RegistrationMagic plugin to version 5.1.9.3 or later.
Yes, you can find more information about CVE-2023-25991 at the following link: [Reference](https://patchstack.com/database/vulnerability/custom-registration-form-builder-with-submission-manager/wordpress-registrationmagic-custom-registration-forms-user-registration-and-user-login-plugin-plugin-5-1-9-2-multiple-cross-site-request-forgery-csrf?_s_id=cve)