5.3
CVE-2024-5149
- EPSS 0.39%
- Veröffentlicht 05.06.2024 05:15:50
- Zuletzt bearbeitet 08.04.2026 19:21:51
- Erkennungen
BuddyForms <= 2.8.9 - Email Verification Bypass due to Insufficient Randomness
BuddyForms <= 2.8.9 - Email Verification Bypass due to Insufficient Randomness
The BuddyForms plugin for WordPress is vulnerable to Email Verification Bypass in all versions up to, and including, 2.8.9 via the use of an insufficiently random activation code. This makes it possible for unauthenticated attackers to bypass the email verification.
Mögliche Gegenmaßnahme
BuddyForms: Update to version 2.8.10, or a newer patched version
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Themekraft ≫ Buddyforms SwPlatform wordpress Version <= 2.8.9
Weitere Schwachstelleninformationen
SystemWordPress Plugin
≫
Produkt
BuddyForms
Version
*-2.8.9
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.39% | 0.304 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| NIST | 5.3 | 3.9 | 1.4 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
|
| security@wordfence.com | 6.5 | 3.9 | 2.5 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
|
CWE-330 Use of Insufficiently Random Values
The product uses insufficiently random numbers or values in a security context that depends on unpredictable numbers.
https://plugins.trac.wordpress.org/browser/buddyforms/tags/2.8.9/includes/wp-insert-user.php#L334
https://www.wordfence.com/threat-intel/vulnerabilities/id/a5c8d361-698b-4abd-bcdd-0361d3fd10c5?source=cve
https://plugins.trac.wordpress.org/changeset/3101478/buddyforms/trunk/includes/wp-insert-user.php
https://www.wordfence.com/threat-intel/vulnerabilities/id/a5c8d361-698b-4abd-bcdd-0361d3fd10c5