CVE-2024-10508

CVSS 3.1 Score 9.8 of 10 (high)

Details

Published Nov 9, 2024
Updated: Nov 12, 2024
CWE ID 230

Summary

CVE-2024-10508 is a privilege escalation vulnerability affecting the RegistrationMagic plugin for WordPress. In versions up to 6.0.2.6, the plugin fails to adequately validate password reset tokens during user account password updates. This flaw enables unauthenticated attackers to manipulate the tokens and reset passwords for any user, including administrators, resulting in unauthorized access to these accounts. This vulnerability poses a significant risk to WordPress websites using the RegistrationMagic plugin and should be addressed promptly by updating to a patched version.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share