BuddyForms <= 2.8.9 - Email Verification Bypass due to Insufficient Randomness
2024-06-04 00:00
István MártonStrategic Overview
StatusPatched in 2.8.10
Affected PluginPost Form – Registration Form – Profile Form for User Profiles – Frontend Content Forms for User Submissions (UGC)
Affected Version
<= 2.8.9CVSS6.5Medium
CVE
CVE-2024-5149Vulnerability Overview
The BuddyForms plugin for WordPress is vulnerable to Email Verification Bypass in all versions up to, and including, 2.8.9 via the use of an insufficiently random activation code. This makes it possible for unauthenticated attackers to bypass the email verification.
Technical Analysis
REMEDIATION: Update to version 2.8.10, or a newer patched version --- IDENTIFIER: CWE-330 (Use of Insufficiently Random Values) The product uses insufficiently random numbers or values in a security context that depends on unpredictable numbers.
External References
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C