CVE-2024-1720
WordPress vulnerability analysis and mitigation

Overview

A stored Cross-Site Scripting (XSS) vulnerability was discovered in the User Registration WordPress plugin versions up to 3.1.4. The vulnerability was disclosed on March 6, 2024, and received a CVE identifier of CVE-2024-1720. This security issue affects the custom registration form functionality of the plugin (Wordfence Intel).

Technical details

The vulnerability has been assigned a CVSS score of 4.7 (Medium severity). The security flaw is characterized as an unauthenticated stored self-based cross-site scripting vulnerability, which requires social engineering to successfully exploit (NVD, Wordfence Intel).

Impact

The impact of this vulnerability is considered very limited due to the requirement of social engineering for successful exploitation. If exploited, it could potentially allow attackers to execute malicious scripts in the context of the affected WordPress site (NVD).

Exploitability

The vulnerability requires social engineering tactics to be successfully exploited, which somewhat limits its potential for widespread abuse. No reports of active exploitation in the wild have been documented as of the disclosure date (NVD).

Mitigation and workarounds

Website administrators running the affected versions of the User Registration plugin should update to a patched version as soon as possible to mitigate this vulnerability (Wordfence Intel).

Additional resources


SourceThis report was generated using AI

Related WordPress vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2024-13784CRITICAL9.8
  • arforms-form-builder
NoYesAug 16, 2026
CVE-2026-17087HIGH7.5
  • wp-travel-engine
NoYesAug 16, 2026
CVE-2026-2497HIGH7.2
  • gallery-plugin
NoYesAug 16, 2026
CVE-2026-17608MEDIUM6.5
  • wp-compress-image-optimizer
NoYesAug 16, 2026
CVE-2026-2357MEDIUM6.4
  • bold-page-builder
NoYesAug 16, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management