← WordPress Vulnerabilities
WordPress security by component

User Registration – Custom Registration Form, Login Form, and User Profile

User Registration – Custom Registration Form, Login Form, and User Profile is a WordPress component with 2 published CVE records in this archive. The latest tracked vulnerability was published Jun 01, 2024; the highest CVE/CNA score is 8.8.

Plugin slug: custom-registration-form-login-form-and-user-profile-wordpress-plugin

CVE-2024-4958: User Registration – Custom Registration Form, Login Form, and User Profile: A security weakness

User Registration – Custom Registration Form, Login Form, and User Profile is affected by a security weakness. Exploitation requires an authenticated WordPress account. The resulting impact depends on how the affected component exposes the vulnerable operation.

PublishedJun 01, 2024
Safe version guidanceSee mitigation notes
Safe version
Jun 01, 2024 CVE-2024-4958
User Registration – Custom Registration Form, Login Form, and User Profile: A security weakness
User Registration – Custom Registration Form, Login Form, and User Profile is affected by a security weakness. Exploitation requires an authenticated WordPress account. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE7.1
NVDPending
May 02, 2024 CVE-2024-2417
User Registration – Custom Registration Form, Login Form, and User Profile: Privilege escalation or authentication bypass
User Registration – Custom Registration Form, Login Form, and User Profile is affected by privilege escalation or authentication bypass. Exploitation requires at least subscriber-level access. A successful request can grant permissions or access that the caller should not possess.
See mitigation notes
CVE8.8
NVDPending