CVE-2020-9456
Last modified
CVE-2020-9456 is a high-severity vulnerability rated 8.8/10 on the CVSS scale. In the RegistrationMagic plugin through 4.6.0.3 for WordPress, the user controller allows remote authenticated users (with minimal privileges) to elevate their privileges to administrator via class_rm_user_controller.php rm_user_edit.. EPSS estimates a 2.51% chance of exploitation in the next 30 days.
Description
In the RegistrationMagic plugin through 4.6.0.3 for WordPress, the user controller allows remote authenticated users (with minimal privileges) to elevate their privileges to administrator via class_rm_user_controller.php rm_user_edit.
Metrics
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Metagauss | Registrationmagic | <= 4.6.0.3 |
References
- https://wpvulndb.com/vulnerabilities/10116Third Party Advisory
- https://www.wordfence.com/blog/2020/03/multiple-vulnerabilities-patched-in-registrationmagic-plugin/Exploit, Third Party Advisory
- https://wpvulndb.com/vulnerabilities/10116Third Party Advisory
- https://www.wordfence.com/blog/2020/03/multiple-vulnerabilities-patched-in-registrationmagic-plugin/Exploit, Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2020-9456?
How severe is CVE-2020-9456?
How do I fix CVE-2020-9456?
How Strix Helps
- Uncovering a hidden BOLA in Appsmith's snapshot logicStrix autonomously discovered a BOLA/IDOR vulnerability in Appsmith's snapshot deletion path.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2020
- CVE-2020-9450An issue was discovered in Acronis True Image 2020 24.5.2251…7.8
- CVE-2020-9451An issue was discovered in Acronis True Image 2020 24.5.2251…5.5
- CVE-2020-9452An issue was discovered in Acronis True Image 2020 24.5.2251…7.8
- CVE-2020-9453In Epson iProjection v2.30, the driver file EMP_MPAU.sys all…5.5
- CVE-2020-9454A CSRF vulnerability in the RegistrationMagic plugin through…8.8
- CVE-2020-9455The RegistrationMagic plugin through 4.6.0.3 for WordPress a…4.3
- CVE-2020-9457The RegistrationMagic plugin through 4.6.0.3 for WordPress a…8.8
- CVE-2020-9458In the RegistrationMagic plugin through 4.6.0.3 for WordPres…8.8
- CVE-2020-9459Multiple Stored Cross-site scripting (XSS) vulnerabilities i…5.4
- CVE-2020-9460Octech Oempro 4.7 through 4.11 allow XSS by an authenticated…5.4
- CVE-2020-9461Octech Oempro 4.7 through 4.11 allow stored XSS by an authen…5.4
- CVE-2020-9462An issue was discovered in all Athom Homey and Homey Pro dev…4.3
Are you affected by CVE-2020-9456?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
