Unauthorized Password Reset in Profile Builder Plugin for WordPress
CVE-2023-2297
Key Information:
- Vendor
Wordpress
- Vendor
- CVE Published:
- 27 April 2023
What is CVE-2023-2297?
The Profile Builder β User Profile & User Registration Forms plugin for WordPress suffers from a vulnerability that allows unauthorized users to reset passwords due to insufficient validation in the password reset functionality. The issue arises from the use of an unencrypted password reset key, which can be easily exploited. Attackers may leverage this flaw in conjunction with other vulnerabilities, such as SQL injection in related plugins or themes, to gain access to user accounts without authorization. It is crucial for site administrators to update to the patched version to safeguard against potential account takeovers.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
Profile Builder β User Profile & User Registration Forms * <= 3.9.0
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved