Unauthorized Password Reset Vulnerability in UserPro Plugin for WordPress
CVE-2023-2449
9.8CRITICAL
Key Information:
- Vendor
- Wordpress
- Vendor
- CVE Published:
- 22 November 2023
Summary
The UserPro plugin for WordPress has a serious vulnerability that allows unauthorized password resets due to flawed password reset functionality. This issue arises from insufficient validation in the password reset process, utilizing plaintext values instead of securely hashed values. As a result, attackers can exploit this flaw by leveraging other vulnerabilities like those found in CVE-2023-2448 or CVE-2023-2446, or even through SQL Injection attacks in other plugins or themes present on the same site. Website administrators are advised to update to patched versions and enhance their security measures to mitigate this risk.
Affected Version(s)
UserPro - Community and User Profile WordPress Plugin * <= 5.1.1
References
CVSS V3.1
Score:
9.8
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
Credit
István Márton