CVE Vulnerabilities

CVE-2024-13818

Insertion of Sensitive Information into Log File

Published: Feb 21, 2025 | Modified: Feb 25, 2025
CVSS 3.x
7.5
HIGH
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu

The Registration Forms – User Registration Forms, Invitation-Based Registrations, Front-end User Profile, Login Form & Content Restriction plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.8.3.9 through publicly exposed log files. This makes it possible for unauthenticated attackers to view potentially sensitive information about users contained in the exposed log files.

Weakness

The product writes sensitive information to a log file.

Affected Software

Name Vendor Start Version End Version
Pie_register Genetechsolutions * 3.8.3.9 (including)

Potential Mitigations

References