cleantalk
Vulnerabilities and Security Researches

RegistrationMagic – Custom Registration Forms, User Registration, Payment, and User Login, CVE-2020-9457

CVE, Research URL

CVE-2020-9457

Published on
Mar 07, 2020
Research Description
The RegistrationMagic plugin through 4.6.0.3 for WordPress allows remote authenticated users (with minimal privileges) to import custom vulnerable forms and change form settings via class_rm_form_settings_controller.php, resulting in privilege escalation.
Affected versions
max 4.6.0.4.
Status
vulnerable