CVE Database /
CVE-2024-5324
CVE · High
CVE-2024-5324 — Login & Register Forms – Popup, Slider, Profile & WooCommerce [easy-login-woocommerce] < 2.7.3
| CVE |
Vulnerability |
Type |
Severity |
Affected |
Fixed in |
Published |
Status |
|
CVE-2024-5324
|
Login & Register Forms – Popup, Slider, Profile & WooCommerce [easy-login-woocommerce] < 2.7.3 |
Missing Authorization |
High
8.8
|
< 2.7.3
|
2.7.3 |
2024-06-05 |
—
|
CVE-2024-5324
A vulnerability exists in the Login/Signup Popup plugin for WordPress, affecting versions 2.7.1 to 2.7.2. An authenticated attacker with Subscriber-level access or higher can exploit this issue by modifying arbitrary options on the affected site, including enabling new user registration and setting the default role for new users to Administrator. This is due to a missing capability check in the 'import_settings' function.
Based on public CVE data (MITRE/NVD).
Scan your WordPress site free
No signup, no credit card — enter your URL and get a security report in seconds.
See the full security page for this plugin
Browse the CVE database
Browse all security findings