CVE-2024-9390: RegistrationMagic < 6.0.2.1 - Stored XSS
The RegistrationMagic WordPress plugin before 6.0.2.1 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfilteredhtml capability is disallowed (for example in multisite setup).
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-9390?
CVE-2024-9390 is considered a high severity vulnerability affecting the RegistrationMagic WordPress plugin.
How do I fix CVE-2024-9390?
To fix CVE-2024-9390, update the RegistrationMagic plugin to version 6.0.2.1 or later.
Who is affected by CVE-2024-9390?
CVE-2024-9390 affects users of the RegistrationMagic WordPress plugin who have high privileges, such as administrators.
What type of vulnerability is CVE-2024-9390?
CVE-2024-9390 is a Stored Cross-Site Scripting vulnerability due to insufficient sanitization and escaping of settings.
Can CVE-2024-9390 be exploited without the unfiltered_html capability?
Yes, CVE-2024-9390 can be exploited even if the unfiltered_html capability is disallowed.