BuddyPress Better Registration <= 1.6 - Authentication Bypass to Administrator
criticalThe BuddyPress Better Registration plugin for WordPress is vulnerable to authentication bypass in all versions up to, and including, 1.6. This is due to sbsr_login_user() function not verifying a user's identity prior to authenticating them. This makes it possible for unauthenticated attackers to log in as any user.
- CVSS:
- 9.8
- Affected:
- up to 1.6
- Fix:
- No patched version reported
- Disclosed:
- Oct 14, 2024