Blog

"Prevention is cheaper than a breach"

Live Vulnerability Intelligence

Threat Database

Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.

Total23
Critical1
High4
Medium18
Reset
Showing 21-23 of 23 records
Threat Entry Updated 2024-11-21

CVE-2023-3343 - User Registration Plugin

The User Registration plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 3.0.1 via deserialization of untrusted input from the 'profile-pic-url' parameter. This allows authenticated attackers, with subscriber-level permissions and above, to inject a PHP Object. No POP chain is present in the vulnerable plugin. If a POP chain is present via an additional plugin or theme installed on the target system, it could allow the attacker to delete arbitrary files, retrieve sensitive data, or execute code.

PLUGIN User Registration

CVE-2023-3343

HIGH CVSS 8.8 2023-07-13
Threat Entry Updated 2024-11-21

CVE-2023-3371 - User Registration Plugin

The User Registration plugin for WordPress is vulnerable to Sensitive Information Exposure due to hardcoded encryption key on the 'lock_content_form_handler' and 'display_password_form' function in versions up to, and including, 3.7.3. This makes it possible for unauthenticated attackers to decrypt and view the password protected content.

PLUGIN User Registration

CVE-2023-3371

MEDIUM CVSS 5.3 2023-06-27
Threat Entry Updated 2024-11-21

CVE-2021-24654 - User Registration Plugin

The User Registration WordPress plugin before 2.0.2 does not properly sanitise the user_registration_profile_pic_url value when submitted directly via the user_registration_update_profile_details AJAX action. This could allow any authenticated user, such as subscriber, to perform Stored Cross-Site attacks when their profile is viewed

PLUGIN User Registration

CVE-2021-24654

MEDIUM CVSS 5.4 2021-10-04
Scroll to top