The User Registration WordPress plugin before 2.12 does not prevent users with at least the contributor role from rendering sensitive shortcodes, allowing them to generate, and leak, valid password reset URLs, which they can use to take over any accounts.
Metrics
Affected Vendors & Products
References
History
Fri, 09 May 2025 12:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Strategy11
Strategy11 user Registration Forms |
|
Weaknesses | NVD-CWE-noinfo | |
CPEs | cpe:2.3:a:strategy11:user_registration_forms:*:*:*:*:*:wordpress:*:* | |
Vendors & Products |
Strategy11
Strategy11 user Registration Forms |
Fri, 01 Nov 2024 19:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
cvssV3_1
|

Status: PUBLISHED
Assigner: WPScan
Published: 2024-03-11T17:56:06.109Z
Updated: 2024-11-01T18:30:42.850Z
Reserved: 2024-02-06T20:07:07.982Z
Link: CVE-2024-1290

Updated: 2024-08-01T18:33:25.378Z

Status : Analyzed
Published: 2024-03-11T18:15:18.003
Modified: 2025-05-09T12:18:34.000
Link: CVE-2024-1290

No data.