First published: Fri Feb 21 2025(Updated: )
The Registration Forms – User Registration Forms, Invitation-Based Registrations, Front-end User Profile, Login Form & Content Restriction plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.8.3.9 through publicly exposed log files. This makes it possible for unauthenticated attackers to view potentially sensitive information about users contained in the exposed log files.
Credit: security@wordfence.com
Affected Software | Affected Version | How to fix |
---|---|---|
WordPress Registration Forms | <=3.8.3.9 | |
Genetechsolutions Pie Register Premium | <=3.8.3.9 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-13818 is considered a medium severity vulnerability due to its potential for sensitive information exposure.
To fix CVE-2024-13818, update the WordPress Registration Forms plugin to version 3.8.4 or later.
CVE-2024-13818 affects all versions of the WordPress Registration Forms plugin up to and including 3.8.3.9.
CVE-2024-13818 is a sensitive information exposure vulnerability that allows unauthorized access to user data.
Any WordPress site using the Registration Forms plugin versions up to 3.8.3.9 may be affected by CVE-2024-13818.