Authentication vulnerability in Registration Forms – User Registration Forms, Invitation-Based Registrations, Front-end User Profile, Login Form & Content Restriction 3.7.1.4

A popular WordPress plugin called “Registration Forms” has a security flaw that allows hackers to log in as any user, even administrators. This is because the plugin does not properly check the user’s identity before allowing them to log in. This vulnerability affects all versions of the plugin up to 3.7.1.4.

Detected in:

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.