CVE-2024-0701 Vulnerability Details

  /     /     /  

CVE-2024-0701 Metadata Quick Info

CVE Published: 05/02/2024 | CVE Updated: 07/11/2024 | CVE Year: 2024
Source: Wordfence | Vendor: n/a | Product: UserPro - Community and User Profile WordPress Plugin
Status : PUBLISHED

CVE-2024-0701 Description

The UserPro plugin for WordPress is vulnerable to Security Feature Bypass in all versions up to, and including, 5.1.6. This is due to the use of client-side restrictions to enforce the \'Disabled registration\' Membership feature within the plugin\'s General settings. This makes it possible for unauthenticated attackers to register an account even when account registration has been disabled by an administrator.

Metrics

CVSS Version: 3.1 | Base Score: 5.3 MEDIUM
Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N

l➤ Exploitability Metrics:
    Attack Vector (AV)*
    Attack Complexity (AC)*
    Privileges Required (PR)*
    User Interaction (UI)*
    Scope (S)*

l➤ Impact Metrics:
    Confidentiality Impact (C)*
    Integrity Impact (I)*
    Availability Impact (A)*

Weakness Enumeration (CWE)

CWE-ID:
CWE Name: CWE-602 Client-Side Enforcement of Server-Side Security
Source: n/a

Common Attack Pattern Enumeration and Classification (CAPEC)

CAPEC-ID:
CAPEC Description:


Source: NVD (National Vulnerability Database).