CVE-2020-9455
Last modified
CVE-2020-9455 is a medium-severity vulnerability rated 4.3/10 on the CVSS scale. The RegistrationMagic plugin through 4.6.0.3 for WordPress allows remote authenticated users (with minimal privileges) to send arbitrary emails on behalf of the site via class_rm_user_services.php send_email_user_view.. EPSS estimates a 1.44% chance of exploitation in the next 30 days.
Description
The RegistrationMagic plugin through 4.6.0.3 for WordPress allows remote authenticated users (with minimal privileges) to send arbitrary emails on behalf of the site via class_rm_user_services.php send_email_user_view.
Metrics
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Metagauss | Registrationmagic | <= 4.6.0.3 |
References
- https://wpvulndb.com/vulnerabilities/10116Third Party Advisory
- https://www.wordfence.com/blog/2020/03/multiple-vulnerabilities-patched-in-registrationmagic-plugin/Exploit, Third Party Advisory
- https://wpvulndb.com/vulnerabilities/10116Third Party Advisory
- https://www.wordfence.com/blog/2020/03/multiple-vulnerabilities-patched-in-registrationmagic-plugin/Exploit, Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2020-9455?
How severe is CVE-2020-9455?
How do I fix CVE-2020-9455?
How Strix Helps
- Uncovering a hidden BOLA in Appsmith's snapshot logicStrix autonomously discovered a BOLA/IDOR vulnerability in Appsmith's snapshot deletion path.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2020
- CVE-2020-9449An insecure random number generation vulnerability in BlaB! …8.8
- CVE-2020-9450An issue was discovered in Acronis True Image 2020 24.5.2251…7.8
- CVE-2020-9451An issue was discovered in Acronis True Image 2020 24.5.2251…5.5
- CVE-2020-9452An issue was discovered in Acronis True Image 2020 24.5.2251…7.8
- CVE-2020-9453In Epson iProjection v2.30, the driver file EMP_MPAU.sys all…5.5
- CVE-2020-9454A CSRF vulnerability in the RegistrationMagic plugin through…8.8
- CVE-2020-9456In the RegistrationMagic plugin through 4.6.0.3 for WordPres…8.8
- CVE-2020-9457The RegistrationMagic plugin through 4.6.0.3 for WordPress a…8.8
- CVE-2020-9458In the RegistrationMagic plugin through 4.6.0.3 for WordPres…8.8
- CVE-2020-9459Multiple Stored Cross-site scripting (XSS) vulnerabilities i…5.4
- CVE-2020-9460Octech Oempro 4.7 through 4.11 allow XSS by an authenticated…5.4
- CVE-2020-9461Octech Oempro 4.7 through 4.11 allow stored XSS by an authen…5.4
Are you affected by CVE-2020-9455?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
