Unauthorized Password Reset Vulnerability in UserPro Plugin for WordPress
CVE-2023-2449

9.8CRITICAL

Key Information:

Vendor
Wordpress
Vendor
CVE Published:
22 November 2023

Summary

The UserPro plugin for WordPress has a serious vulnerability that allows unauthorized password resets due to flawed password reset functionality. This issue arises from insufficient validation in the password reset process, utilizing plaintext values instead of securely hashed values. As a result, attackers can exploit this flaw by leveraging other vulnerabilities like those found in CVE-2023-2448 or CVE-2023-2446, or even through SQL Injection attacks in other plugins or themes present on the same site. Website administrators are advised to update to patched versions and enhance their security measures to mitigate this risk.

Affected Version(s)

UserPro - Community and User Profile WordPress Plugin * <= 5.1.1

References

CVSS V3.1

Score:
9.8
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

István Márton
.