Unauthorized Password Reset Vulnerability in UserPro Plugin for WordPress
CVE-2023-2449
Key Information:
- Vendor
Wordpress
- Vendor
- CVE Published:
- 22 November 2023
What is CVE-2023-2449?
The UserPro plugin for WordPress has a serious vulnerability that allows unauthorized password resets due to flawed password reset functionality. This issue arises from insufficient validation in the password reset process, utilizing plaintext values instead of securely hashed values. As a result, attackers can exploit this flaw by leveraging other vulnerabilities like those found in CVE-2023-2448 or CVE-2023-2446, or even through SQL Injection attacks in other plugins or themes present on the same site. Website administrators are advised to update to patched versions and enhance their security measures to mitigate this risk.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
UserPro - Community and User Profile WordPress Plugin * <= 5.1.1
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved