2022-06-22 03:45:30 +00:00
id : wp-registration-enabled
info :
2023-02-06 21:51:58 +00:00
name : WordPress User Registration Panel - Detect
2022-06-22 03:45:30 +00:00
author : tess,DhiyaneshDK
severity : info
description : |
2023-02-06 21:51:58 +00:00
WordPress user registration is currently configured so that anyone can register as a user, thereby enabling an attacker to possibly access sensitive data and execute unathorized operations.
2022-06-22 03:45:30 +00:00
remediation : |
2023-02-06 21:51:58 +00:00
Disable user registration if not needed. To do so, log in as an administrator and go to Settings -> General and uncheck "Anyone can register."
2022-06-22 03:54:00 +00:00
reference :
- https://www.acunetix.com/vulnerabilities/web/wordpress-user-registration-enabled/
2023-02-06 21:51:58 +00:00
classification :
cvss-metrics : CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:N
2023-10-14 11:27:55 +00:00
cvss-score : 0
2023-02-06 21:51:58 +00:00
cwe-id : CWE-200
2022-06-22 03:54:00 +00:00
metadata :
verified : true
2023-10-14 11:27:55 +00:00
max-request : 1
2022-06-22 03:45:30 +00:00
tags : wordpress,wp,misconfig
2023-04-27 04:28:59 +00:00
http :
2022-06-22 03:45:30 +00:00
- method : GET
path :
- "{{BaseURL}}/wp-login.php"
matchers-condition : and
matchers :
- type : word
part : body
words :
- '?action=register"'
- type : word
part : header
words :
- 'text/html'
- type : status
status :
- 200