CVE Radar Logo
CVERadar
CVE Radar Logo
CVERadar

CVE-2024-10508

Medium Severity
Metagauss
SVRS
36/100

CVSSv3
NA/10

EPSS
0.04995/1

CVE-2024-10508 is a critical privilege escalation vulnerability in the RegistrationMagic WordPress plugin. The flaw allows unauthenticated attackers to reset passwords of any user, including admins, due to improper validation of the password reset token.

This account takeover vulnerability affects all RegistrationMagic versions up to 6.0.2.6. With a SOCRadar Vulnerability Risk Score (SVRS) of 36, this vulnerability, while not immediately critical, still presents a significant risk. Successful exploitation grants attackers full control over affected WordPress sites. Given that the CVE has been tagged as "In The Wild," immediate investigation and patching are highly recommended to mitigate potential damage and unauthorized access. The associated risk is unauthorized access and complete compromise of the WordPress site, allowing for malicious activities such as data theft, website defacement, or malware distribution.

In The Wild
2024-11-09

2025-01-29
Eye Icon
SOCRadar
AI Insight

Description

CVE-2024-10508 affects the RegistrationMagic – User Registration Plugin with Custom Registration Forms plugin for WordPress, exposing a critical privilege escalation vulnerability via account takeover. This flaw allows unauthenticated attackers to reset the password of any user, including administrators, by exploiting a weakness in the password reset token validation process. This vulnerability has been observed in the wild, highlighting the urgent need for immediate action.

Key Insights

  • Severity: While the CVSS score is 9.8, the SOCRadar Vulnerability Risk Score (SVRS) of 36 suggests a moderate severity. This discrepancy highlights the importance of a multi-faceted assessment that considers factors beyond purely technical aspects.
  • Account Takeover: The vulnerability allows attackers to take over any user account, including administrators. This grants attackers full access to the WordPress site and its data, potentially leading to data theft, website defacement, or launching further attacks.
  • Unauthenticated Exploitation: The attack does not require any prior authentication, making it easier for attackers to exploit the vulnerability. This increases the risk of successful attacks, as attackers can target any WordPress site running the vulnerable RegistrationMagic plugin.
  • Active Exploitation: The CVE is labeled "In The Wild," indicating active exploitation by hackers. This signifies immediate action is required to mitigate the threat.

Mitigation Strategies

  • Update the Plugin: Immediately upgrade to the latest version of the RegistrationMagic plugin (6.0.2.7 or later), which includes a fix for the vulnerability.
  • Implement Strong Passwords: Encourage users to use strong, unique passwords and enable two-factor authentication for all accounts.
  • Regular Security Audits: Conduct regular security audits to detect and remediate vulnerabilities, ensuring the plugin is kept up-to-date.
  • Monitor Security Logs: Closely monitor security logs for any suspicious activities related to user account changes or attempts to reset passwords.

Additional Information

If users have additional queries regarding this incident, they can use the 'Ask to Analyst' feature, contact SOCRadar directly, or open a support ticket for more information if necessary.

Indicators of Compromise

No IOCs found for this CVE

Exploits

No exploits found for this CVE

Enhance Your CVE Management with SOCRadar Vulnerability Intelligence
Get comprehensive CVE details, real-time notifications, and proactive threat management all in one platform.
CVE Details
Access comprehensive CVE information instantly
Real-time Tracking
Subscribe to CVEs and get instant updates
Exploit Analysis
Monitor related APT groups and threats
IOC Tracking
Analyze and track CVE-related IOCs

News

CVE-2024-10508 | metagauss RegistrationMagic Plugin up to 6.0.2.6 on WordPress Password Reset Token missing values
vuldb.com2024-11-09
CVE-2024-10508 | metagauss RegistrationMagic Plugin up to 6.0.2.6 on WordPress Password Reset Token missing values | A vulnerability, which was classified as critical, has been found in metagauss RegistrationMagic Plugin up to 6.0.2.6 on WordPress. Affected by this issue is some unknown functionality of the component Password Reset Token Handler. The manipulation leads to improper handling of missing values. This vulnerability is handled as CVE-2024-10508
vuldb.com
rss
forum
news

Social Media

CVE-2024-10508 The RegistrationMagic – User Registration Plugin with Custom Registration Forms plugin for WordPress is vulnerable to privilege escalation via account takeover in all… https://t.co/61UObAjNGx
0
0
0
[CVE-2024-10508: CRITICAL] WordPress plugin RegistrationMagic up to version 6.0.2.6 is vulnerable to privilege escalation via account takeover due to improper password reset token validation, enabling attackers t...#cybersecurity,#vulnerability https://t.co/2kkgARF3ti https://t.co/AoXMXKAjwU
0
0
0

Affected Software

Configuration 1
TypeVendorProduct
AppMetagaussregistrationmagic

References

ReferenceLink
[email protected]https://plugins.trac.wordpress.org/browser/custom-registration-form-builder-with-submission-manager/tags/6.0.2.6/public/controllers/class_rm_login_controller.php#L239
[email protected]https://plugins.trac.wordpress.org/browser/custom-registration-form-builder-with-submission-manager/tags/6.0.2.6/public/controllers/class_rm_login_controller.php#L241
[email protected]https://plugins.trac.wordpress.org/changeset/3181174/custom-registration-form-builder-with-submission-manager/trunk/public/controllers/class_rm_login_controller.php
[email protected]https://www.wordfence.com/threat-intel/vulnerabilities/id/c4679fa7-be6b-4f50-8cdf-ff9822794f19?source=cve

CWE Details

CWE IDCWE NameDescription
CWE-230Improper Handling of Missing ValuesThe software does not handle or incorrectly handles when a parameter, field, or argument name is specified, but the associated value is missing, i.e. it is empty, blank, or null.

CVE Radar

Real-time CVE Intelligence & Vulnerability Management Platform

CVE Radar provides comprehensive vulnerability intelligence by monitoring CVE databases, security advisories, and threat feeds. Get instant updates on new vulnerabilities, exploit details, and mitigation strategies specific to your assets.

Get Free Vulnerability Intelligence AccessAccess real-time CVE monitoring, exploit analysis, and threat intelligence