First published: Tue Jun 27 2023(Updated: )
The User Registration plugin for WordPress is vulnerable to Sensitive Information Exposure due to hardcoded encryption key on the 'lock_content_form_handler' and 'display_password_form' function in versions up to, and including, 3.7.3. This makes it possible for unauthenticated attackers to decrypt and view the password protected content.
Credit: security@wordfence.com
Affected Software | Affected Version | How to fix |
---|---|---|
Wpdeveloper Embedpress | <=3.7.3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID of this vulnerability is CVE-2023-3371.
The severity of CVE-2023-3371 is high with a score of 7.5.
The affected software of CVE-2023-3371 is the User Registration plugin for WordPress up to and including version 3.7.3.
CVE-2023-3371 is a vulnerability in the User Registration plugin for WordPress that allows unauthenticated attackers to decrypt sensitive information due to a hardcoded encryption key.
Yes, updating the User Registration plugin for WordPress to a version higher than 3.7.3 will fix the vulnerability.