CVE-2023-52209: WordPress WPForms User Registration plugin <= 2.1.0 - Authenticated Privilege Escalation vulnerability
Published Aug 1, 2024
·Updated
Improper Privilege Management vulnerability in WPForms, LLC. WPForms User Registration allows Privilege Escalation.This issue affects WPForms User Registration: from n/a through 2.1.0.
Affected Software
2 affected components
WPForms User Registration<=2.1.0
WordPress WPForms User Registration<=2.1.0
Remediation
Information
Update to 2.1.2 or a higher version.
Event History
Aug 1, 2024
CVE Published
via MITRE·09:04 PM
Data Sourced
via MITRE·09:04 PM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·09:15 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2023-52209?
CVE-2023-52209 has a moderate severity level due to its potential for privilege escalation.
2
How do I fix CVE-2023-52209?
To fix CVE-2023-52209, update your WPForms User Registration plugin to version 2.1.1 or later.
3
What versions are affected by CVE-2023-52209?
CVE-2023-52209 affects all versions of WPForms User Registration up to and including 2.1.0.
4
Can CVE-2023-52209 be exploited remotely?
CVE-2023-52209 requires authenticated access, meaning an attacker must have a valid account to exploit the vulnerability.
5
What type of vulnerability is CVE-2023-52209?
CVE-2023-52209 is classified as an Improper Privilege Management vulnerability.