
Cloud Vulnerability DB
A community-led vulnerabilities database
A stored Cross-Site Scripting (XSS) vulnerability was discovered in the User Registration WordPress plugin versions up to 3.1.4. The vulnerability was disclosed on March 6, 2024, and received a CVE identifier of CVE-2024-1720. This security issue affects the custom registration form functionality of the plugin (Wordfence Intel).
The vulnerability has been assigned a CVSS score of 4.7 (Medium severity). The security flaw is characterized as an unauthenticated stored self-based cross-site scripting vulnerability, which requires social engineering to successfully exploit (NVD, Wordfence Intel).
The impact of this vulnerability is considered very limited due to the requirement of social engineering for successful exploitation. If exploited, it could potentially allow attackers to execute malicious scripts in the context of the affected WordPress site (NVD).
The vulnerability requires social engineering tactics to be successfully exploited, which somewhat limits its potential for widespread abuse. No reports of active exploitation in the wild have been documented as of the disclosure date (NVD).
Website administrators running the affected versions of the User Registration plugin should update to a patched version as soon as possible to mitigate this vulnerability (Wordfence Intel).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."