The RegistrationMagic plugin through 4.6.0.3 for WordPress allows remote authenticated users (with minimal privileges) to import custom vulnerable forms and change form settings via class_rm_form_settings_controller.php, resulting in privilege escalation.
History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: mitre

Published: 2020-03-06T18:56:35

Updated: 2020-03-06T18:57:19

Reserved: 2020-02-28T00:00:00


Link: CVE-2020-9457

JSON object: View

cve-icon NVD Information

Status : Analyzed

Published: 2020-03-06T19:15:11.813

Modified: 2022-01-21T20:58:39.297


Link: CVE-2020-9457

JSON object: View

cve-icon Redhat Information

No data.

CWE