Vulnerabilities > Metagauss > High
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2023-05-16 | CVE-2023-2548 | Authorization Bypass Through User-Controlled Key vulnerability in Metagauss Registrationmagic The RegistrationMagic plugin for WordPress is vulnerable to Insecure Direct Object References in versions up to, and including, 5.2.0.5. | 7.2 |
2023-03-20 | CVE-2023-0940 | Incorrect Authorization vulnerability in Metagauss Profilegrid The ProfileGrid WordPress plugin before 5.3.1 provides an AJAX endpoint for resetting a user password but does not implement proper authorization. | 8.8 |
2023-03-13 | CVE-2023-25991 | Unspecified vulnerability in Metagauss Registrationmagic Cross-Site Request Forgery (CSRF) vulnerability in RegistrationMagic plugin <= 5.1.9.2 versions. | 8.8 |
2022-11-17 | CVE-2022-41791 | Improper Neutralization of Formula Elements in a CSV File vulnerability in Metagauss Profilegrid Auth. | 8.8 |
2022-03-07 | CVE-2022-0420 | SQL Injection vulnerability in Metagauss Registrationmagic The RegistrationMagic WordPress plugin before 5.0.2.2 does not sanitise and escape the rm_form_id parameter before using it in a SQL statement in the Automation admin dashboard, allowing high privilege users to perform SQL injection attacks | 7.2 |
2022-01-10 | CVE-2021-24862 | Unspecified vulnerability in Metagauss Registrationmagic The RegistrationMagic WordPress plugin before 5.0.1.6 does not escape user input in its rm_chronos_ajax AJAX action before using it in a SQL statement when duplicating tasks in batches, which could lead to a SQL injection issue | 7.2 |
2021-12-14 | CVE-2021-4073 | Unspecified vulnerability in Metagauss Registrationmagic The RegistrationMagic WordPress plugin made it possible for unauthenticated users to log in as any site user, including administrators, if they knew a valid username on the site due to missing identity validation in the social login function social_login_using_email() of the plugin. | 8.1 |
2020-03-12 | CVE-2020-8435 | SQL Injection vulnerability in Metagauss Registrationmagic 4.6.0.0 An issue was discovered in the RegistrationMagic plugin 4.6.0.0 for WordPress. | 8.1 |
2020-03-06 | CVE-2020-9458 | Missing Authorization vulnerability in Metagauss Registrationmagic In the RegistrationMagic plugin through 4.6.0.3 for WordPress, the export function allows remote authenticated users (with minimal privileges) to export submitted form data and settings via class_rm_form_controller.php rm_form_export. | 8.8 |
2020-03-06 | CVE-2020-9457 | Missing Authorization vulnerability in Metagauss Registrationmagic The RegistrationMagic plugin through 4.6.0.3 for WordPress allows remote authenticated users (with minimal privileges) to import custom vulnerable forms and change form settings via class_rm_form_settings_controller.php, resulting in privilege escalation. | 8.8 |