CVE-2024-6069: Pie Register - Basic <= 3.8.3.4 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Plugin Installation
The Registration Forms – User Registration Forms, Invitation-Based Registrations, Front-end User Profile, Login Form & Content Restriction plugin for WordPress is vulnerable to unauthorized arbitrary plugin installation due to a missing capability check on the pieregisterinstalladdon function in all versions up to, and including, 3.8.3.4. This makes it possible for authenticated attackers, with subscriber-level access and above, to install arbitrary plugins. As a result attackers might achieve code execution on the targeted server
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Pie Register - Basicto a version that resolves this vulnerability.Fixed in 3.8.3.4
Event History
Frequently Asked Questions
What is the severity of CVE-2024-6069?
CVE-2024-6069 has a high severity level due to its potential for unauthorized arbitrary plugin installation.
How can I fix CVE-2024-6069?
To fix CVE-2024-6069, update the affected plugins to their latest versions where capability checks are implemented.
Which versions are affected by CVE-2024-6069?
CVE-2024-6069 affects versions up to and including 3.8.3.4 of the vulnerable plugins.
What type of vulnerability is CVE-2024-6069?
CVE-2024-6069 is an unauthorized access vulnerability that allows arbitrary actions on the plugin.
Who is impacted by CVE-2024-6069?
Individuals and organizations using the affected versions of the Registration Forms plugin for WordPress are at risk.