CVE-2024-49604: WordPress Simple User Registration plugin <= 6.7 - Broken Authentication vulnerability
Published Oct 20, 2024
·Updated
Authentication Bypass Using an Alternate Path or Channel vulnerability in N-Media Simple User Registration wp-registration allows Authentication Bypass.This issue affects Simple User Registration: from n/a through <= 6.7.
Affected Software
1 affected component
Najeebmedia Memberhero Wordpress<=5.5
Event History
Oct 20, 2024
CVE Published
via MITRE·07:56 AM
Data Sourced
via MITRE·07:56 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·08:15 AM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2024-49604?
CVE-2024-49604 has been rated as a high severity vulnerability due to its potential for allowing authentication bypass.
2
How do I fix CVE-2024-49604?
To fix CVE-2024-49604, update the Simple User Registration plugin to the latest version beyond 5.5.
3
What versions are affected by CVE-2024-49604?
CVE-2024-49604 affects Najeeb Ahmad Simple User Registration versions up to and including 5.5.
4
Can CVE-2024-49604 lead to unauthorized access?
Yes, CVE-2024-49604 can lead to unauthorized access by allowing attackers to bypass authentication measures.
5
Is there a workaround for CVE-2024-49604?
There are no officially recommended workarounds for CVE-2024-49604 other than upgrading the plugin.