CVE-2024-5149: BuddyForms <= 2.8.9 - Email Verification Bypass due to Insufficient Randomness
The BuddyForms plugin for WordPress is vulnerable to Email Verification Bypass in all versions up to, and including, 2.8.9 via the use of an insufficiently random activation code. This makes it possible for unauthenticated attackers to bypass the email verification.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
wordpress/BuddyFormsto a version that resolves this vulnerability.Fixed in 2.8.9 - Compensating control
Protect the WordPress site so unauthenticated attackers cannot access or register in ways that rely on the BuddyForms email verification flow until the plugin is remediated.
Event History
Frequently Asked Questions
What is the severity of CVE-2024-5149?
CVE-2024-5149 is classified as a high-severity vulnerability due to its potential for unauthorized account access.
How do I fix CVE-2024-5149?
To fix CVE-2024-5149, update the BuddyForms plugin to version 2.9.0 or later where the vulnerability has been patched.
Who is affected by CVE-2024-5149?
Any user of the BuddyForms plugin for WordPress versions up to and including 2.8.9 is affected by CVE-2024-5149.
What type of attack does CVE-2024-5149 enable?
CVE-2024-5149 enables unauthenticated attackers to bypass the email verification process.
Is there a workaround for CVE-2024-5149?
There is no recommended workaround for CVE-2024-5149; updating the plugin is the only effective mitigation.