2022-06-22 03:45:30 +00:00
id : wp-registration-enabled
info :
2023-02-06 21:51:58 +00:00
name : WordPress User Registration Panel - Detect
2022-06-22 03:45:30 +00:00
author : tess,DhiyaneshDK
severity : info
description : |
2023-02-06 21:51:58 +00:00
WordPress user registration is currently configured so that anyone can register as a user, thereby enabling an attacker to possibly access sensitive data and execute unathorized operations.
2022-06-22 03:45:30 +00:00
remediation : |
2023-02-06 21:51:58 +00:00
Disable user registration if not needed. To do so, log in as an administrator and go to Settings -> General and uncheck "Anyone can register."
2022-06-22 03:54:00 +00:00
reference :
- https://www.acunetix.com/vulnerabilities/web/wordpress-user-registration-enabled/
2023-02-06 21:51:58 +00:00
classification :
cvss-metrics : CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:N
2023-10-14 11:27:55 +00:00
cvss-score : 0
2023-02-06 21:51:58 +00:00
cwe-id : CWE-200
2022-06-22 03:54:00 +00:00
metadata :
verified : true
2023-10-14 11:27:55 +00:00
max-request : 1
2022-06-22 03:45:30 +00:00
tags : wordpress,wp,misconfig
2023-04-27 04:28:59 +00:00
http :
2022-06-22 03:45:30 +00:00
- method : GET
path :
- "{{BaseURL}}/wp-login.php"
matchers-condition : and
matchers :
- type : word
part : body
words :
- '?action=register"'
- type : word
part : header
words :
- 'text/html'
- type : status
status :
- 200
2023-10-20 11:41:13 +00:00
# digest: 490a00463044022048337db0ecfd45c74e3cebfdde24c2b2d2116b0c7d45984c6a923f902a8b9614022048bcc319224343e18ed5ec98c42475cd777e9f9f399bc3d06d88c5f509decee0:922c64590222798bb761d5b6d8e72950