CVE · High

CVE-2024-5324 — Login & Register Forms – Popup, Slider, Profile & WooCommerce [easy-login-woocommerce] < 2.7.3

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2024-5324 Login & Register Forms – Popup, Slider, Profile & WooCommerce [easy-login-woocommerce] < 2.7.3 Missing Authorization High 8.8 < 2.7.3 2.7.3 2024-06-05

CVE-2024-5324

A vulnerability exists in the Login/Signup Popup plugin for WordPress, affecting versions 2.7.1 to 2.7.2. An authenticated attacker with Subscriber-level access or higher can exploit this issue by modifying arbitrary options on the affected site, including enabling new user registration and setting the default role for new users to Administrator. This is due to a missing capability check in the 'import_settings' function.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.