Unauthorized Password Reset Vulnerability in UserPro Plugin for WordPress
CVE-2023-2449
9.8CRITICAL
Key Information:
- Vendor
Wordpress
- Vendor
- CVE Published:
- 22 November 2023
What is CVE-2023-2449?
The UserPro plugin for WordPress has a serious vulnerability that allows unauthorized password resets due to flawed password reset functionality. This issue arises from insufficient validation in the password reset process, utilizing plaintext values instead of securely hashed values. As a result, attackers can exploit this flaw by leveraging other vulnerabilities like those found in CVE-2023-2448 or CVE-2023-2446, or even through SQL Injection attacks in other plugins or themes present on the same site. Website administrators are advised to update to patched versions and enhance their security measures to mitigate this risk.
Affected Version(s)
UserPro - Community and User Profile WordPress Plugin * <= 5.1.1