CVE-2024-10508
CVSS 3.1 Score 9.8 of 10 (high)
Details
Summary
CVE-2024-10508 is a privilege escalation vulnerability affecting the RegistrationMagic plugin for WordPress. In versions up to 6.0.2.6, the plugin fails to adequately validate password reset tokens during user account password updates. This flaw enables unauthenticated attackers to manipulate the tokens and reset passwords for any user, including administrators, resulting in unauthorized access to these accounts. This vulnerability poses a significant risk to WordPress websites using the RegistrationMagic plugin and should be addressed promptly by updating to a patched version.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.